csrf-absence

1 article
sort: new top best
clear filter
0 8/10

A persistent XSS vulnerability on eBay's My World profile section exploited a blacklist-based HTML filter that failed to block deprecated tags like <plaintext>, <fn>, and <credit>. The attacker chained this with event handlers, String.fromCharCode/eval to bypass character limits, missing CSRF protection, and unHTTPOnly cookies to create a self-propagating worm that could steal session tokens.

eBay myworld.ebay.com plaintext fn credit
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details