ssid-injection

1 article
sort: new top best
clear filter
0 6/10

XSS vulnerability in Avast/AVG antivirus firewall notification feature that reflects unsanitized SSID names, allowing attackers to execute arbitrary JavaScript via crafted wireless network SSIDs. The vulnerability affects Avast Internet Security v19.3.2369+ and AVG Internet Security v19.3.3084+ on Windows, and was rewarded with a $5,000 bounty.

CVE-2019-18653 CVE-2019-18654 Avast AVG AntiVirus YoKo Kho BruteLogic s0md3v Deral Heiland BlackHat Europe 2013
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details