embed-payload

1 article
sort: new top best
clear filter
0 6/10

Three XSS vulnerabilities discovered in ProtonMail's iOS app affecting different origins (applewebdata, data, and javascript URIs) with various payloads including SVG onload handlers and embedded base64-encoded HTML, enabling JavaScript execution and potential phishing attacks through email messages.

ProtonMail Vladimir Metnew DOMPurify Cure53 CVE-2016-1764 Anatoly Andy Yen Safiler WebKit
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details