microsoft-edge

1 article
sort: new top best
clear filter
0 7/10

A CSP bypass vulnerability in Microsoft Edge (CVE-2017-0135) where attackers could abuse the XSS filter's default mode to disable meta-tag-based CSP policies by appending malicious meta elements as URL parameters, causing the filter to neuterase the legitimate CSP declaration and allow script execution.

CVE-2017-0135 MS17-007 Microsoft Edge Internet Explorer 8 Xiaoyin Liu MSRC FreeBuf
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details