Stealing passwords from infosec Mastodon - without bypassing CSP
portswigger.net | research | #credential-theft | #web-security | #xss | #html-injection | #sanitization | #mastodon
Summary
How an HTML injection in Infosec Mastodon's post filter enabled credential theft without bypassing CSP, abusing quirks in the platform's HTML handling such as title attributes and emoji substitution.
- Published
- Collected
Skip to content