script-injection

2 articles
sort: new top best
clear filter
0 7/10

A persistent XSS vulnerability was discovered in PayPal's Braintree payment gateway where the cancelUrl parameter was reflected in script context on the PayPal login page without proper sanitization. By escaping quote characters and injecting HTML5 event listeners, attackers could implement keylogging to steal passwords despite PayPal's Content Security Policy restrictions by using postMessage API.

PayPal Braintree Casper Sleep Inc. braintree/web/3.9.0
wesecureapp.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

A detailed writeup presenting five real-world XSS vulnerabilities across different web applications, showcasing evasion techniques including mobile DOM-events not covered by blacklists, hidden input attribute injection, WAF bypass through incomplete tag closure with script src attributes, and the importance of testing overlooked functionality.

Oleksandr Opanasiuk
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details