server-side-xss

1 article
sort: new top best
clear filter
0 8/10

XSS vulnerability in dynamically generated PDF endpoint where unsanitized user input (utrnumber parameter) is rendered as HTML/JavaScript in PDFs, allowing arbitrary JavaScript execution under file:// origin and enabling local file read via XMLHttpRequest to access /etc/passwd.

Rahul Maini Bugcrowd xyz.com
noob.ninja · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details