Web Hack List

Collected research

#309531 Stored XSS in Snapmatic + R★Editor comments

Rockstar Games disclosed on HackerOne: Stored XSS in Snapmatic +...

Six months of stored XSS against Rockstar Games Social Club, Snapmatic and Rockstar Editor comments, each round defeating a stricter web application firewall. The bypasses used control characters inside tag names, a stray percent sign that desynchronised the escaper, and full-width, small-form and CJK angle brackets that a later layer best-fit mapped back to a less-than sign.

Record

Document
Rockstar Games disclosed on HackerOne: Stored XSS in Snapmatic +...
Researcher
europa
Published by
HackerOne
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of europa, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .