Ambushed by AngularJS: a hidden CSP bypass in Piwik PRO
portswigger.net | research | #web-security | #dom-xss | #csp-bypass | #angularjs | #piwik-pro | #script-gadget
Summary
A DOM Invader audit of Piwik PRO uncovered an AngularJS-based debugger whose script gadgets can bypass CSP; with an HTML injection, events like ng-focus could execute code despite the policy.
- Published
- Collected
Skip to content