Web Hack List

Collected research

Client Side Path Traversal (CSPT) Bug Bounty Reports and Techniques

Six bug bounty cases of client-side path traversal: front-end code builds an API path from a URL segment, so backslashes, double-encoded dots or router quirks send the fetch to a different endpoint. Pairing that with an open redirect or an uploaded JSON or image file to control the response gives DOM XSS, spoofed content and account takeover.

Record

Researcher
Renwa and @RenwaX23
Published by
Medium
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Renwa and @RenwaX23, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .