DOM XSS to Account Takeover: Not-So-Dirty Dancing in GIS SDK
It was just another bug hunting session on a public program. The scope wasn't huge - only a couple of domains to work with - but that's often where you find the best bugs. I had been grinding on this program for about 8 hours total, with roughly 6 of...
blog.voorivex.team9 min read
Adam Noverian
On first image. How did you find that code? Didn't regex like that happen on backend?