Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Abusing JavaScript frameworks to bypass XSS mitigations

Summary

Gareth Heyes abuses the Mavo JavaScript framework's $url object to build DOM-based XSS that bypasses NoScript's XSS filter, and shows risks from attacker-controlled data sources.
Published
Collected

original ↗

Related coverage

back