Exploiting XSS in hidden inputs and meta tags
portswigger.net | research | #web-security | #xss | #chrome | #popover-api | #hidden-inputs | #meta-tags
Summary
Abusing Chrome's new popover API to exploit XSS in hidden inputs and meta tags: onbeforetoggle events fire on popover targets, bypassing attribute blocklists and enabling script execution.
- Published
- Collected
Skip to content