Collected research
Prototype Pollution and bypassing client-side HTML sanitizers
Securitum. Leading european penetration testing company
Client-side HTML sanitizers read their allow-lists from configuration objects, so a prototype pollution primitive can add tags and attributes back in. DOMPurify, sanitize-html, js-xss and Google Closure are each bypassed this way, turning pollution into XSS, and Closure can additionally be pointed at an attacker-hosted script path.
Record
- Document
- Securitum. Leading european penetration testing company
- Researcher
- Michał Bentkowski
- Published by
- securitum.com
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Michał Bentkowski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .