Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2024-52597] Stored Cross-Site Scripting (XSS) in 2FAuth

Summary

Documents how XBOW reached stored XSS in 2FAuth (CVE-2024-52597) through SVG uploads in the QR-code decoder, after working around authentication, and validated it in a headless browser.
Published
Collected

original ↗

Related coverage

back