hyperlink-injection

1 article
sort: new top best
clear filter
0 5/10

A stored XSS vulnerability in Outlook.com iOS browsers was exploited by crafting a PowerPoint file (saved in 97-2003 format) with a javascript: protocol hyperlink, which executes when the document is opened and the link is clicked within the iOS browser. The researcher earned $1,000 USD from Microsoft's bug bounty program.

outlook.com outlook.live.com Microsoft Google Chrome Safari Firefox Opera @omespino
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 14 hours ago · details