output-encoding

2 articles
sort: new top best
clear filter
0 7/10
vulnerability

A reflected XSS vulnerability was discovered in Microsoft Dynamics 365's "Personal Document Template: Information" page, where user first and last name fields were reflected without proper encoding, allowing malicious JavaScript execution when victims viewed the template information page.

Microsoft Dynamics 365 Tim Kent Microsoft Security Response Center Azure AD
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 8/10

A researcher discovered a blind XSS vulnerability in GoDaddy's internal customer support panel by injecting XSS payloads into user profile fields (first/last name), which executed when support agents accessed the CRM system. The vulnerability allowed arbitrary actions on customer accounts including domain transfers and account deletion, demonstrating how data poisoning can compromise backend systems drawing from shared data stores.

GoDaddy XSS Hunter Cobalt BeEF crm.int.godaddy.com sso.godaddy.com
thehackerblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details