csv-injection

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered stored XSS vulnerability in a file upload feature restricted to CSV files by bypassing server-side XSS filters using a polyglot payload combining HTML/SVG tags and event handlers.

HackerOne Gujjuboy10x00
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details