mail.ru

1 article
sort: new top best
clear filter
0 6/10

A stored XSS vulnerability was discovered in Mail.ru's .eml file parsing functionality, where the subject field from uploaded email files was reflected without sanitization, allowing attackers to inject JavaScript that executes when victims open the malicious message. The vulnerability could be weaponized as an XSS worm to steal session cookies and act on behalf of logged-in users.

Mail.ru Seif Elsallamy Seekurity HackerOne CVE-2017-5244
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 14 hours ago · details