Hacker News
- DOMPurify bypass: XSS via HTML namespace confusion https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/ 81 comments
Linking pages
- LEXSS: Bypassing Lexical Parsing Security Controls | Bishop Fox https://labs.bishopfox.com/tech-blog/lexss-bypassing-lexical-parsing-security-controls 2 comments
- Safe DOM manipulation with the Sanitizer API https://web.dev/sanitizer/ 1 comment
- Practical guide to XHTML https://www.nayuki.io/page/practical-guide-to-xhtml 0 comments
- mXSS: The Vulnerability Hiding in Your Code | Sonar https://www.sonarsource.com/blog/mxss-the-vulnerability-hiding-in-your-code/ 0 comments
Linked pages
- GitHub - cure53/DOMPurify: DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: https://github.com/cure53/DOMPurify 0 comments
- Write-up of DOMPurify 2.0.0 bypass using mutation XSS - research.securitum.com https://research.securitum.com/dompurify-bypass-using-mxss/ 0 comments
Related searches:
Search whole site: site:research.securitum.com
Search title: Mutation XSS via namespace confusion - DOMPurify < 2.0.17 bypass - research.securitum.com
See how to search.