Collected research
XSS in GMail's AMP4Email via DOM Clobbering
AMP4Email in Gmail allowed the id attribute, so DOM clobbering was possible. Two anchors sharing an id yield an HTMLCollection whose members can be addressed by name, and an anchor stringifies to its href, letting an attacker clobber the AMP_MODE and testLocation globals and point AMP's script loader at an attacker URL for XSS.
Record
- Researcher
- @SecurityMB
- Published by
- research.securitum.com
- Date
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @SecurityMB, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .