Modify the request path to bypass upload restrictions, leading to an XSS vulnerability.

6 months ago 55
BOOK THIS SPACE FOR AD
ARTICLE AD

Xiaodong

1 min read

Just now

--

Hello hackers

this time I bring a simple article mainly to share an XSS vulnerability I discovered through uploading in a bug bounty project.

The target has a customer service system, as well as some places to collect user feedback. I found that their interfaces are all the same.

Read Entire Article