A security research writeup documenting improper input handling in a web application's search functionality. The application fails to sanitize or encode user-supplied input, enabling reflected XSS, DOM-based XSS, and HTML injection. Additionally, crafted inputs expose internal backend details such as private IP addresses and

4m read timeFrom infosecwriteups.com
Post cover image
Table of contents
SummaryGet Aditya Bhatt ’s stories in your inbox

Sort: