web-application-vulnerability

1 article
sort: new top best
clear filter
0 8/10

A creative XSS exploitation technique that transforms a reflected/stored XSS vulnerability in Swisscom's Bluewin webmail into a self-propagating worm via malicious attachment filenames. The worm leverages unescaped angle brackets in attachment metadata to inject JavaScript that can automatically enumerate and send itself to other users' contacts.

Swisscom Bluewin webmail.bluewin.ch rich-v01.bluewin.ch Nicolas Heiniger Alexandre Florian BlackAlps
blog.compass-security.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details