keylogging

2 articles
sort: new top best
clear filter
0 7/10

A persistent XSS vulnerability was discovered in PayPal's Braintree payment gateway where the cancelUrl parameter was reflected in script context on the PayPal login page without proper sanitization. By escaping quote characters and injecting HTML5 event listeners, attackers could implement keylogging to steal passwords despite PayPal's Content Security Policy restrictions by using postMessage API.

PayPal Braintree Casper Sleep Inc. braintree/web/3.9.0
wesecureapp.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 5/10

A researcher discovered a stored XSS vulnerability in Optimizely's experiment preview feature that allowed injecting malicious JavaScript to log keystrokes from a different domain (optimizelypreview.com) by embedding scripts in the user's website.

Armaan Pathan Optimizely cobalt.io
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details