⤷ Title: Vaulting over a .innerHTML sink in a Locked-Down CSP
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Sun, 27 Apr 2025 19:33:48 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Sun, 27 Apr 2025 19:33:48 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
Medium
Vaulting over a .innerHTML sink in a Locked-Down CSP
This writeup explores a CSP Bypass with script-src whitelisted assets inside a .innerHTML DOM sink.
⤷ Title: Vaulting over a .innerHTML sink in a Locked-Down CSP
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 05:42:44 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 05:42:44 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
Medium
Vaulting over a .innerHTML sink in a Locked-Down CSP
This writeup explores a CSP Bypass with script-src whitelisted assets inside a .innerHTML DOM sink.
⤷ Title: React에서 발생할 수 있는 XSS 공격
════════════════════════
𐀪 Author: 김정운
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 02:03:23 GMT
════════════════════════
⌗ Tags: #xss_attack #react #dangerouslysetinnerhtml #innerhtml #xs
════════════════════════
𐀪 Author: 김정운
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 02:03:23 GMT
════════════════════════
⌗ Tags: #xss_attack #react #dangerouslysetinnerhtml #innerhtml #xs
Medium
React에서 발생할 수 있는 XSS 공격
그리고 해결방안
⤷ Title: Death of the XSS Bug? Firefox 148 Debuts the Sanitizer API to Neutralize Malicious Scripts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 04:39:35 +0000
════════════════════════
⌗ Tags: #Technology #AppSec #Cross_Site Scripting #CWE_79 #Firefox 148 #infosec #innerHTML #mozilla #Sanitizer API #setHTML #Web Security #XSS Prevention
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 04:39:35 +0000
════════════════════════
⌗ Tags: #Technology #AppSec #Cross_Site Scripting #CWE_79 #Firefox 148 #infosec #innerHTML #mozilla #Sanitizer API #setHTML #Web Security #XSS Prevention
Daily CyberSecurity
Death of the XSS Bug? Firefox 148 Debuts the Sanitizer API to Neutralize Malicious Scripts
Mozilla Firefox 148 launches the standardized Sanitizer API. Discover how the new setHTML() method systematically strips XSS attacks to protect web users.