This SIMPLE trick will exploit image uploads - $2500 TikTok bug bounty.

Stored XSS in SVG files.

Roberto
InfoSec Write-ups
Published in
3 min readAug 25, 2022

--

DALL·E “Cyberpunk digital art of a hacker on a computer.”
DALL·E “Cyberpunk digital art of a hacker on a computer.”

Summary

Cross-site Scripting (XSS) is a security headache for all web application developers. In this type of vulnerability, attackers will somehow inject malicious JavaScript code, or “scripts,” into a benign web app. If the attacker can successfully embed the script…

--

--

Stanford alum, Software Engineer with a passion for CyberSec, Biotech, and Sustainability. Work with me at https://www.tidallabs.io/.