Collected research
Client Side Path Traversal (CSPT) Bug Bounty Reports and Techniques
Six bug bounty cases of client-side path traversal: front-end code builds an API path from a URL segment, so backslashes, double-encoded dots or router quirks send the fetch to a different endpoint. Pairing that with an open redirect or an uploaded JSON or image file to control the response gives DOM XSS, spoofed content and account takeover.
Record
- Researcher
- Renwa and @RenwaX23
- Published by
- Medium
- Date
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Renwa and @RenwaX23, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .