
Yaniv Nizry
50 posts









📁🫷🚧Can't control the extension of a file upload, but you want an XSS? Read more on how we overcame this obstacle to further exploit entire organizations using Fortinet endpoint protection: sonarsource.com/blog/caught-in… #appsec #vulnerability #bugbountytips


🕸️🏢Caught in the FortiNet: Exploiting Fortinet’s endpoint protection solution to compromise an entire organization using minimal user interaction. Dive into our technical analysis of this interesting attack scenario: sonarsource.com/blog/caught-in… #appsec #security #vulnerability

🕸️🏢Caught in the FortiNet: Exploiting Fortinet’s endpoint protection solution to compromise an entire organization using minimal user interaction. Dive into our technical analysis of this interesting attack scenario: sonarsource.com/blog/caught-in… #appsec #security #vulnerability





🧵 [1/4] Here is our DOMPurify 3.2.1 bypass, using a namespace confusion technique where each element is initially in a “correct” namespace. When it was allowed, the ‘is’ attribute was not handled correctly, making the attribute content’s regex check obsolete. #mXSS #XSS







