Concealing payloads in URL credentials
portswigger.net | research | #firefox | #web-security | #dom-xss | #credentials | #url-parsing | #clobbering
Summary
Payloads concealed in URL credentials stay invisible in Chrome and Firefox address bars, persisting through same-origin navigation; document.URL exposes them, enabling DOM XSS and clobbering.
- Published
- Collected
Skip to content