protocol-relative-url

1 article
sort: new top best
clear filter
0 5/10
bug-bounty

A DOM XSS vulnerability in a private program where unsanitized location.pathname is used to construct AJAX requests, allowing attackers to redirect requests to attacker-controlled domains and inject malicious scripts via protocol-relative URLs (//attacker.com).

jinone.github.io · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details