Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

LEXSS: Bypassing Lexical Parsing Security Controls

Summary

Introducing LEXSS: XSS that bypasses lexical sanitizers by abusing mismatches between HTML parsing and lexical parsing, letting special HTML tags run JavaScript where filters were believed effective.
Published
Collected

original ↗

Related coverage

back