Bypassing CSP with policy injection
portswigger.net | research | #bug-bounty | #portswigger | #chrome | #csp-bypass | #paypal | #edge | #policy-injection
Summary
Gareth Heyes injects directives into PayPal's CSP via a token parameter in report-uri, dropping Edge's whole policy with a stray semicolon and overriding Chrome's script-src for a $900 bounty.
- Published
- Collected
Skip to content