uri-scheme-bypass

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered a blind stored XSS vulnerability in a form-building service by bypassing quote filters using the javascript: URI scheme merged with legitimate URLs, allowing arbitrary JavaScript execution on admin pages. The technique leverages acceptance of alternative URI schemes (javascript:https://) combined with rendering in anchor tags to inject payloads that execute when accessed by form creators.

Youssef A. Mohamed GeneralEG CESPPA Squnity Synack
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details