unboiled.info
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
N7x@infosec.pub to appsec@infosec.pubEnglish · 3 years ago

Exploiting XSS in hidden inputs and meta tags

portswigger.net

external-link
message-square
0
link
fedilink
1
external-link

Exploiting XSS in hidden inputs and meta tags

portswigger.net

N7x@infosec.pub to appsec@infosec.pubEnglish · 3 years ago
message-square
0
link
fedilink
In this post we are going to show how you can (ab)use the new HTML popup functionality in Chrome to exploit XSS in meta tags and hidden inputs. It all started when I noticed the new popover behaviour

appsec@infosec.pub

appsec@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !appsec@infosec.pub

A community for all things related to application security.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 5 users / day
  • 5 users / week
  • 5 users / month
  • 5 users / 6 months
  • 0 local subscribers
  • 382 subscribers
  • 50 Posts
  • 0 Comments
  • Modlog
  • mods:
  • laszlok@infosec.pub
  • UI: unknown version
  • BE: 0.19.15
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org