dom-manipulation

2 articles
sort: new top best
clear filter
0 8/10

XSS vulnerability in dynamically generated PDF endpoint where unsanitized user input (utrnumber parameter) is rendered as HTML/JavaScript in PDFs, allowing arbitrary JavaScript execution under file:// origin and enabling local file read via XMLHttpRequest to access /etc/passwd.

Rahul Maini Bugcrowd xyz.com
noob.ninja · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10
vulnerability

Reflected XSS vulnerability in Google Code Jam's scoreboard page that fires in toast messages, exploitable in browsers without CSP support (e.g., IE), allowing attackers to hijack victim accounts and modify profile information through DOM manipulation.

Google Code Jam Thomas Orlita gstatic.com
websecblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details