html-attributes

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered a stored XSS vulnerability on a payment processing form by bypassing input filters that blocked angle brackets and parentheses. The payload used HTML event attributes (OnMouseOver) with backtick-based function calls to execute JavaScript when a user interacts with the input field.

Prial Islam Khan
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details