wallet-transfer

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered how to escalate a self-XSS vulnerability in a wallet transfer function into a reflected XSS by encoding the payload as a QR code, bypassing the plaintext visibility constraint and enabling exploitation of other users.

HackerOne Hein Thant Zin
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details