Web Hack List

Collected research

2023 Microsoft Office XSS

Shows that Office's online-video service inserts an attacker-controlled YouTube title into an iframe title attribute without escaping. Word renders the result in Edge WebView with script-capable sandbox flags, allowing JavaScript execution and invocation of registered URI schemes.

Record

Researcher
PKSecurity
Published by
PKSecurity
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of PKSecurity, first published at the original source. Preserved copies are kept so the citation survives its host.