meeting-platform

1 article
sort: new top best
clear filter
0 8/10
vulnerability

XSS vulnerability in a conference application (likely Zoom or similar) that chains to RCE via Node.js process execution in the native OS X client. The exploit uses String.fromCharCode to bypass quote filtering and jQuery's $.getScript() to fetch and execute remote code that spawns arbitrary processes.

ActBlue RSnake patrick ben greg GitHub Node jQuery String.fromCharCode process.open xor.cc
matatall.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details