1.
pwn.ai | vulnerability | | original ↗ | #vulnerability-research | #account-takeover | #stored-xss | #jspwiki
CVE-2022-24948: how a tricky stored XSS in JSPWiki's username field was exploited via a meta-tag focus trick that avoids colons, escalating pre-auth injection toward account takeover.
Skip to content