Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Edge XSS filter bypass

Summary

Gareth Heyes explains an unfixed Edge XSS filter bypass combining a legacy IE location-object trick with ES6 computed property names to obfuscate toString/valueOf. Reported to Microsoft in 2015.
Published
Collected

original ↗

Related coverage

back