Web Hack List

Collected research

Stealing passwords from infosec Mastodon without bypassing CSP

Finds that emoji placeholder expansion after HTML filtering can break a title attribute and inject arbitrary markup into a Mastodon fork. With scripts blocked by CSP, hidden autofilled login fields and a spoofed action bar submit saved credentials to an attacker when the victim clicks.

Record

Published by
PortSwigger Research
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of PortSwigger Research, first published at the original source. Preserved copies are kept so the citation survives its host.