event-handler-bypass

2 articles
sort: new top best
clear filter
0 5/10

A researcher bypassed Practo's XSS firewall by discovering that the 'oncopy' event handler was not blocked, allowing HTML injection and XSS via the payload <vipin oncopy=prompt(document.domain)>. The vulnerability was reported and fixed quickly.

Practo Vipin Chaudhary brutelogic
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

Researcher bypassed imgur.com's XSS protection by combining stripped <script> tags with event handlers (SVG onload) to achieve stored XSS. The bypass exploited the application's character-filtering logic by nesting disallowed tags within each other to reconstruct the malicious payload after sanitization.

imgur.com Armaan Pathan HackerOne InfoSec Write-ups
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details