Web Hack List

Collected research

LEXSS: Bypassing Lexical Parsing Security Controls

HTML sanitisers that re-parse markup can be desynchronised from the browser's own parser. Nesting tags that switch tokenizer state, such as an iframe wrapping a textarea, or entering the MathML namespace, makes the sanitiser treat active content as harmless text, so the final parse executes it. Shown against TinyMCE and Froala.

Record

Researcher
@bishopfox
Published by
Bishop Fox
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @bishopfox, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .