Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Exploiting XSS in hidden inputs and meta tags

Summary

Abusing Chrome's new popover API to exploit XSS in hidden inputs and meta tags: onbeforetoggle events fire on popover targets, bypassing attribute blocklists and enabling script execution.
Published
Collected

original ↗

Related coverage

back