Collected research
2023 Microsoft Office XSS
Shows that Office's online-video service inserts an attacker-controlled YouTube title into an iframe title attribute without escaping. Word renders the result in Edge WebView with script-capable sandbox flags, allowing JavaScript execution and invocation of registered URI schemes.
Record
- Researcher
- PKSecurity
- Published by
- PKSecurity
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of PKSecurity, first published at the original source. Preserved copies are kept so the citation survives its host.