Field
Real bug-bounty disclosures and technique breakdowns — distilled from the field.
highXSS3 min read
Stored XSS via Markdown image onerror in a comment field
The sanitizer allowed img tags but not their attributes — except onerror slipped through a parser quirk.
an
anon· 3 min readRead writeup