xss-attack

1 article
sort: new top best
clear filter
0 6/10

A stored XSS vulnerability in a HackerOne program where a refclickid URL parameter is unsanitized and stored in Set-Cookie headers, then later reflected in JSON responses within script tags, allowing attackers to inject arbitrary JavaScript that executes on victim browsers.

Arbaz Hussain HackerOne
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details