bug-bounty480
google300
xss277
microsoft251
facebook213
rce160
apple150
exploit137
bragging-post102
account-takeover98
malware95
csrf84
cve80
privilege-escalation75
stored-xss65
authentication-bypass64
writeup61
reflected-xss57
browser55
react54
cloudflare51
ssrf51
phishing51
dos50
access-control49
input-validation48
cross-site-scripting48
node47
docker46
aws46
smart-contract45
sql-injection45
ethereum44
supply-chain44
defi43
web-security43
oauth41
web-application41
web339
burp-suite36
lfi35
vulnerability-disclosure34
idor34
html-injection33
race-condition32
smart-contract-vulnerability32
clickjacking31
reverse-engineering31
csp-bypass30
information-disclosure30
0
6/10
vulnerability
A Medium-severity XSS vulnerability in an article embedding feature that exploits the Referer header value being reflected in the response body without proper sanitization. The attack succeeds only in Internet Explorer due to its lack of URL encoding in the Referer header, allowing script injection via a malicious referrer URL.
xss
cross-site-scripting
referer-header
internet-explorer
url-encoding
browser-vulnerability
embed-vulnerability
client-side
Arbaz Hussain
HackerOne
Internet Explorer
Chrome
Firefox