twitter-cards

1 article
sort: new top best
clear filter
0 9/10

A researcher discovered a stored XSS vulnerability in Twitter that could be weaponized as a self-propagating worm by exploiting flawed HTML tag stripping in the Welcome Message deeplink feature, combined with a JSONP endpoint vulnerability on a whitelisted subdomain to bypass the CSP policy. The attack chained multiple input validation bypasses and DOM manipulation techniques to achieve arbitrary JavaScript execution.

Twitter Virtue Security CVE (not specified in article)
virtuesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details