Bypass Filters using Prototype Pollution
Use prototype pollution to bypass the “js-xss” sanitizer.
Use prototype pollution to bypass the “js-xss” sanitizer.
How could two security features collide into a vulnerability?
The main goal is to bypass CSP, CSRF protection and an restricted charset.
Using javascript labels and SVG elements to execute arbitrary code in Firefox.
Exposed source maps lead to arbirary code execution.