finance

1 article
sort: new top best
clear filter
0 6/10

Researcher discovered a reflected XSS vulnerability on Yahoo Finance mobile version by bypassing a filter that converted payloads to uppercase, using HTML character encoding (alert) to obfuscate the alert function and execute JavaScript.

yahoo.com finance.yahoo.com Samuel @saamux
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details