location-header-injection

1 article
sort: new top best
clear filter
0 7/10

CVE-2019-17004 is a semi-universal XSS vulnerability in Firefox for iOS that allowed attackers to execute JavaScript on arbitrary origins by exploiting insufficient checks on JavaScript execution via Location response headers, originating from the bookmarklets functionality. The vulnerability was also found in Brave for iOS and both vendors patched it after responsible disclosure.

CVE-2019-17004 Firefox for iOS Brave for iOS Safari Chrome Mozilla Cliqz
0x65.dev · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details