Collected research
#309531 Stored XSS in Snapmatic + R★Editor comments
Rockstar Games disclosed on HackerOne: Stored XSS in Snapmatic +...
Six months of stored XSS against Rockstar Games Social Club, Snapmatic and Rockstar Editor comments, each round defeating a stricter web application firewall. The bypasses used control characters inside tag names, a stray percent sign that desynchronised the escaper, and full-width, small-form and CJK angle brackets that a later layer best-fit mapped back to a less-than sign.
Record
- Document
- Rockstar Games disclosed on HackerOne: Stored XSS in Snapmatic +...
- Researcher
- europa
- Published by
- HackerOne
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of europa, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .