[CVE-2024-52597] Stored Cross-Site Scripting (XSS) in 2FAuth
xbow.com | vulnerability | CVE-2024-52597 | #vulnerability-research | #open-source | #xss | #svg-upload | #2fauth | #cve-2024-52597
Summary
Documents how XBOW reached stored XSS in 2FAuth (CVE-2024-52597) through SVG uploads in the QR-code decoder, after working around authentication, and validated it in a headless browser.
- Published
- Collected
Skip to content