javascript-uri

2 articles
sort: new top best
clear filter
0 8/10

DOM-based XSS vulnerability in Google Crisis Map discovered by bypassing client-side URL validation via request interception, then chained with missing X-Frame-Options header to enable clickjacking attacks on published maps. The vulnerability required users to click through an overlaid iframe to trigger JavaScript execution.

Google Crisis Map google.org Thomas Orlita Fiddler Burp Suite
websecblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

Firefox iOS QR code scanner fails to sanitize javascript: URIs, allowing XSS attacks across multiple contexts including reader mode, local files, and internal pages, while also bypassing Content Security Policy restrictions. The vulnerability was fixed by removing javascript URI support from the address bar in later versions.

CVE-2019-17003 Firefox iOS Opera Mini WebKit Mozilla
payatu.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details