Collected research
Stealing passwords from infosec Mastodon without bypassing CSP
Finds that emoji placeholder expansion after HTML filtering can break a title attribute and inject arbitrary markup into a Mastodon fork. With scripts blocked by CSP, hidden autofilled login fields and a spoofed action bar submit saved credentials to an attacker when the victim clicks.
Record
- Published by
- PortSwigger Research
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of PortSwigger Research, first published at the original source. Preserved copies are kept so the citation survives its host.