html-comment-injection

1 article
sort: new top best
clear filter
0 5/10
bug-bounty

First valid reflected XSS vulnerability found via HTML comment injection by discovering that user-supplied URL paths were reflected in commented-out strings in page source, allowing script tag injection through comment closure payloads.

HackerOne Jatin Nandwana
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details