microsoft-office

1 article
sort: new top best
clear filter
0 5/10

A stored XSS vulnerability was discovered in Outlook.com's iOS browser implementation when viewing crafted PowerPoint files containing JavaScript protocol hyperlinks. The attack requires uploading a specially formatted .ppt file (saved as 97-2003 format) with a malicious javascript: URL, which executes when clicked in the email attachment viewer on iOS browsers.

outlook.com outlook.live.com Microsoft Google Chrome Safari Firefox Opera @omespino
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details