# XSS

Published articles for XSS.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## \[webapps\] Bludit CMS - Stored XSS

DevFeed: [\[webapps\] Bludit CMS - Stored XSS](<https://devfeed.tech/articles/webapps-bludit-cms-stored-xss-34763.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52670>)

Author: Saud Alenazi

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Content Management System](<https://devfeed.tech/topics/cms.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cms](<https://devfeed.tech/tags/cms.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A concise exploit entry describing stored cross-site scripting (XSS) in Bludit CMS for web applications across multiple platforms.

### Source excerpt

Bludit CMS - Stored XSS

## \[webapps\] CubeCart 6.7.4 - Stored XSS

DevFeed: [\[webapps\] CubeCart 6.7.4 - Stored XSS](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-stored-xss-34755.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52662>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-54645](<https://devfeed.tech/tags/cve-2026-54645.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

An exploit entry for CubeCart 6.7.4 describing a stored cross-site scripting vulnerability identified as CVE-2026-54645. It is categorized as a web applications exploit for multiple platforms.

### Source excerpt

CubeCart 6.7.4 - Stored XSS

## \[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)

DevFeed: [\[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)](<https://devfeed.tech/articles/webapps-c-mor-6-0104-cross-site-scripting-xss-34758.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52665>)

Author: Samir Shamdin

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51133](<https://devfeed.tech/tags/cve-2026-51133.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A C-MOR 6.0104 entry documenting a Cross-Site Scripting (XSS) exploit identified as CVE-2026-51133.

### Source excerpt

C-MOR 6.0104 - Cross-Site Scripting (XSS)

## Keycloak 26.6.4 released

DevFeed: [Keycloak 26.6.4 released](<https://devfeed.tech/articles/keycloak-26-6-4-released-31778.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/06/keycloak-2664-released>)

Author: Keycloak Team

Published: 2026-06-26T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [idm](<https://devfeed.tech/tags/idm.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [reference](<https://devfeed.tech/tags/reference.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Keycloak 26.6.4 is released with security fixes addressing privilege escalation, information disclosure, cross-site scripting, authentication and authorization bypasses, and other issues. The release also upgrades Quarkus to 3.33.2.1.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin #50345 CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing #50347 CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass #50349 CVE-2026-9705 Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token #50350 CVE-2026-9795 Keycloak: keycloak: privilege escalation via improper scope mapping enforcement #50351 CVE-2026-9799 Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass #50352 CVE-2026-9800 Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison #50357 CVE-2026-11800 Keycloak: Authentication bypass via JWT algorithm confusion Enhancements #50100 Upgrade to Quarkus 3.33.2.1 Bugs #47999 [Keycloak JavaScript CI] - Build Keycloak ci #49639 Keycloak Admin Client tests fails in CI ci #49700 Incorrect migration guide reference docs #49707 Cannot build project due to ISPN protoschema and 26.2 branch infinispan #49733 keycloak-api-docs-dist is not deployable dist/quarkus

## Security Risks in Modern JavaScript Frameworks: React, Dependencies, and Client-Side Data Handling

DevFeed: [Security Risks in Modern JavaScript Frameworks: React, Dependencies, and Client-Side Data Handling](<https://devfeed.tech/articles/hidden-security-risks-in-modern-javascript-frameworks-17759.md>)

Original publisher: [Read original article](<https://talent500.com/blog/javascript-framework-security-risks-react-teams/>)

Author: snehaa

Published: 2026-06-10T09:09:52Z

Content type: article

Language: en

Sources: [Backend Archives | Talent500 blog](<https://devfeed.tech/sources/backend-archives-talent500-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [React](<https://devfeed.tech/topics/react.md>), [Web](<https://devfeed.tech/topics/web.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [backend](<https://devfeed.tech/tags/backend.md>), [csp](<https://devfeed.tech/tags/csp.md>), [framework-vulnerabilities](<https://devfeed.tech/tags/framework-vulnerabilities.md>), [frontend](<https://devfeed.tech/tags/frontend.md>), [frontend-security](<https://devfeed.tech/tags/frontend-security.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [javascript-security](<https://devfeed.tech/tags/javascript-security.md>), [newsletters](<https://devfeed.tech/tags/newsletters.md>), [npm-security](<https://devfeed.tech/tags/npm-security.md>), [react](<https://devfeed.tech/tags/react.md>), [react-security](<https://devfeed.tech/tags/react-security.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [technology](<https://devfeed.tech/tags/technology.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

The article examines security risks in modern JavaScript applications, focusing on React data handling, dangerous DOM sinks, dependency supply-chain complexity, and configuration issues that can contribute to XSS, injection, data leakage, and vulnerable code reaching production.

### Source excerpt

Modern JavaScript frameworks have transformed how web applications are built, but they have also introduced new, less visible security risks. [...] The post Hidden Security Risks in Modern JavaScript Frameworks appeared first on Talent500 blog.

## Keycloak 26.6.2 released

DevFeed: [Keycloak 26.6.2 released](<https://devfeed.tech/articles/keycloak-26-6-2-released-31772.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/05/keycloak-2662-released>)

Author: Keycloak Team

Published: 2026-05-19T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [XSS](<https://devfeed.tech/topics/xss.md>)

Tags: [2](<https://devfeed.tech/tags/2.md>), [2026](<https://devfeed.tech/tags/2026.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [permission](<https://devfeed.tech/tags/permission.md>), [pii](<https://devfeed.tech/tags/pii.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Keycloak 26.6.2 is a security-focused release that fixes multiple vulnerabilities, including denial-of-service issues, request smuggling, access-control flaws, stored XSS, WebAuthn policy bypass, token disclosure, account takeover, and PII enumeration. It also includes enhancements and bug fixes.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service #47486 CVE-2026-33870 RFC violation: HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing #47932 [CVE-2026-4628] Improper Access Control on Keycloak Server through UMA resource management endpoints via PUT parameters authorization-services #48049 [CVE-2026-37980] Stored XSS in select-organization.ftl - FreeMarker HTML-escape insufficient in inline JS handler organizations #48275 CVE-2026-5588 Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules core #48388 [CVE-2026-6856] Acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration authentication/webauthn #48570 [CVE-2026-0636, CVE-2026-3505, CVE-2026-5598] Multiple bouncycastle CVEs core #49108 [CVE-2026-7307] Denial of service when sending a crafted request to the /saml endpoint #49109 [CVE-2026-7504] Security Vulnerability Report: Redirect URI Validation Bypass in Keycloak #49110 [CVE-2026-7571] Access token disclosure and implicit flow bypass via forged client data #49111 [CVE-2026-7507] Session fixation in OIDC login flow leading to account takeover #49112 [CVE-2026-37982] Execute-actions token replay allows unauthorized WebAuthn credential enrollment on victim account #49113 [CVE-2026-37979] OIDC Introspection endpoint does not enforce audience restriction, leaking claims from lightweight access tokens #49114 [CVE-2026-37978] Cross-role PII leakage via evaluate-scopes endpoints bypasses user view permission #49115 [CVE-2026-4630] Keycloak Authorization Services Protection API IDOR (Cross-Resource Server Access) #49116 [CVE-2026-37981] Broken Access Control in Account Resources User Lookup allows PII enumeration Enhancements #47728 Monitor backups for CNPG -

## Mintlify Security Event - November 2025

DevFeed: [Mintlify Security Event - November 2025](<https://devfeed.tech/articles/mintlify-security-event-november-2025-31113.md>)

Original publisher: [Read original article](<https://www.mintlify.com/blog/working-with-security-researchers-november-2025>)

Author: Han Wang

Published: 2025-12-18T00:00:00Z

Content type: article

Language: en

Sources: [Mintlify Blog](<https://devfeed.tech/sources/mintlify-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [incident](<https://devfeed.tech/topics/incident.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [incident](<https://devfeed.tech/tags/incident.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Mintlify describes how security researchers identified a cross-domain XSS vulnerability in its static asset hosting in November 2025. The company deployed a fix within 45 minutes, purged caches, audited hosted assets, notified potentially affected customers, and collaborated with the researchers on testing and further security improvements.

### Source excerpt

How a week-long collaboration with security researchers helped us identify and fix vulnerabilities, making Mintlify more secure for everyone.

## Welcome to AI pentesting - add on-demand AI assistance directly to your workflow with new, agentic Burp AI capabilities

DevFeed: [Welcome to AI pentesting - add on-demand AI assistance directly to your workflow with new, agentic Burp AI capabilities](<https://devfeed.tech/articles/welcome-to-ai-pentesting-add-on-demand-ai-assistance-directly-to-your-workflow-with-new-agentic-burp-ai-capabilities-7755.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/welcome-to-ai-pentesting-add-on-demand-ai-assistance-directly-to-your-workflow-with-new-agentic-burp-ai-capabilities>)

Author: Amelia Coen

Published: 2025-09-24T14:17:34Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tools](<https://devfeed.tech/tags/tools.md>), [validation](<https://devfeed.tech/tags/validation.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workflow](<https://devfeed.tech/tags/workflow.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

The article introduces agentic Burp AI capabilities that provide on-demand assistance within penetration-testing workflows. Burp AI can explain behavior, suggest attack ideas and payloads, validate findings, analyze request and response data, automate repetitive tasks, and help test for vulnerabilities such as stored XSS while keeping the tester in control.

### Source excerpt

Whether you're navigating a client pentest or chasing a bounty target, even the most experienced testers hit roadblocks, burn time on repetitive tasks, or just want a second opinion. Burp AI is design

## Astro 5.9

DevFeed: [Astro 5.9](<https://devfeed.tech/articles/astro-5-9-3250.md>)

Original publisher: [Read original article](<https://astro.build/blog/astro-590/>)

Author: Emanuele Stoppa; Matt Kane

Published: 2025-06-05T00:00:00Z

Content type: release

Language: en

Sources: [The Astro Blog](<https://devfeed.tech/sources/the-astro-blog.md>)

Topics: [Astro](<https://devfeed.tech/topics/astro.md>), [Security](<https://devfeed.tech/topics/security.md>), [Markdown](<https://devfeed.tech/topics/markdown.md>), [Web Development](<https://devfeed.tech/topics/web-development.md>)

Tags: [astro](<https://devfeed.tech/tags/astro.md>), [cli](<https://devfeed.tech/tags/cli.md>), [csp](<https://devfeed.tech/tags/csp.md>), [markdown](<https://devfeed.tech/tags/markdown.md>), [security](<https://devfeed.tech/tags/security.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Astro 5.9 introduces experimental Content Security Policy support, Markdown rendering in content loaders, optional removal of default styles for experimental responsive images, and adapter controls for suppressing feature-support logs.

### Source excerpt

Astro 5.9 has got your site on lockdown, with experimental support for Content Security Policy, rendering Markdown in content loaders, and more!

## Document My Pentest: you hack, the AI writes it up!

DevFeed: [Document My Pentest: you hack, the AI writes it up!](<https://devfeed.tech/articles/document-my-pentest-you-hack-the-ai-writes-it-up-7675.md>)

Original publisher: [Read original article](<https://portswigger.net/research/document-my-pentest>)

Author: Gareth Heyes

Published: 2025-04-23T13:17:24Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Extension](<https://devfeed.tech/topics/extension.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Web](<https://devfeed.tech/topics/web.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Regular expression](<https://devfeed.tech/topics/regular-expression.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [extension](<https://devfeed.tech/tags/extension.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

The article introduces Document My Pentest, an open-source Burp Suite extension that uses Burp AI features to observe web-security testing activity in real time and build a structured audit trail. It describes generating reports with AI and explains prototype lessons, including difficulties analyzing complete requests and responses, successful detection of clear Path Traversal evidence, and a regex-based approach for identifying reflected input. The approach worked for some reflected-data cases but was not suitable for attacks such as Request Smuggling.

### Source excerpt

Tired of repeating yourself? Automate your web security audit trail. In this post I'll introduce a new Burp AI extension that takes the boring bits out of your pen test. Web security testing can be a

## Shadow Repeater:AI-enhanced manual testing

DevFeed: [Shadow Repeater:AI-enhanced manual testing](<https://devfeed.tech/articles/shadow-repeater-ai-enhanced-manual-testing-7697.md>)

Original publisher: [Read original article](<https://portswigger.net/research/shadow-repeater-ai-enhanced-manual-testing>)

Author: Gareth Heyes

Published: 2025-02-20T13:20:19Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Extension](<https://devfeed.tech/topics/extension.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [automatic](<https://devfeed.tech/tags/automatic.md>), [code](<https://devfeed.tech/tags/code.md>), [extension](<https://devfeed.tech/tags/extension.md>), [github](<https://devfeed.tech/tags/github.md>), [request](<https://devfeed.tech/tags/request.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Shadow Repeater is a Burp Repeater extension that enhances manual security testing with AI-powered automatic variation testing. It analyzes changed parameters and payloads, generates variants through an AI model, tests them against the target, and uses response diffing to identify potentially interesting behavior and vulnerabilities.

### Source excerpt

Have you ever wondered how many vulnerabilities you've missed by a hair's breadth, due to a single flawed choice? We've just released Shadow Repeater, which enhances your manual testing with AI-powere

## Top 10 web hacking techniques of 2024

DevFeed: [Top 10 web hacking techniques of 2024](<https://devfeed.tech/articles/top-10-web-hacking-techniques-of-2024-7709.md>)

Original publisher: [Read original article](<https://portswigger.net/research/top-10-web-hacking-techniques-of-2024>)

Author: James Kettle

Published: 2025-02-04T15:01:48Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Cache](<https://devfeed.tech/topics/cache.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [LocalStorage](<https://devfeed.tech/topics/localstorage.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [cache](<https://devfeed.tech/tags/cache.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [cookies](<https://devfeed.tech/tags/cookies.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [web](<https://devfeed.tech/tags/web.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This annual community-powered review identifies notable web security research and hacking techniques from 2024. The supplied excerpts discuss OAuth flow hijacking through Cookie Tossing, risks involving cookies and JavaScript's Same-Origin Policy, and a ChatGPT account takeover using inconsistent decoding, path traversal, and Web Cache Deception.

### Source excerpt

Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

## Stealing HttpOnly cookies with the cookie sandwich technique

DevFeed: [Stealing HttpOnly cookies with the cookie sandwich technique](<https://devfeed.tech/articles/stealing-httponly-cookies-with-the-cookie-sandwich-technique-7701.md>)

Original publisher: [Read original article](<https://portswigger.net/research/stealing-httponly-cookies-with-the-cookie-sandwich-technique>)

Author: Zakhar Fedotkin

Published: 2025-01-22T14:45:11Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [Cross-origin resource sharing (CORS)](<https://devfeed.tech/topics/cors.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [cors](<https://devfeed.tech/tags/cors.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web](<https://devfeed.tech/tags/web.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This security research describes the "cookie sandwich" technique, which abuses legacy cookie parsing, quoted values, and browser behavior to bypass the HttpOnly flag on certain servers. By manipulating cookie structure, reflected parameters, analytics identifiers, CORS requests with credentials, or same-origin XSS, an attacker may expose sensitive HttpOnly cookie values to client-side scripts.

### Source excerpt

In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie

## Snyk Code Improves Contextual Dataflow Analysis for Taint Vulnerabilities

DevFeed: [Snyk Code Improves Contextual Dataflow Analysis for Taint Vulnerabilities](<https://devfeed.tech/articles/analyze-taint-analysis-faster-with-improved-contextual-dataflow-in-snyk-code-7818.md>)

Original publisher: [Read original article](<https://snyk.io/blog/analyze-taint-analysis-contextual-dataflow-snyk-code/>)

Author: Liran Tal

Published: 2024-10-10T05:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [data](<https://devfeed.tech/tags/data.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [feature](<https://devfeed.tech/tags/feature.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Snyk Code introduces an improved contextual dataflow view for taint vulnerabilities. The update highlights the critical steps in a dataflow path so developers can assess potential true positives and address security issues more efficiently.

### Source excerpt

Snyk Code's enhanced dataflow analysis simplifies vulnerability identification and remediation. Learn how this powerful tool streamlines the security process and saves developers valuable time.

## Building a Real-Time Chat Application with WebSockets

DevFeed: [Building a Real-Time Chat Application with WebSockets](<https://devfeed.tech/articles/building-a-real-time-chat-application-with-websockets-28412.md>)

Original publisher: [Read original article](<https://banes.dev/building-a-real-time-chat-application-with-websockets/>)

Author: admin

Published: 2024-05-06T07:40:48Z

Content type: tutorial

Language: en

Sources: [Posts on Chris Banes](<https://devfeed.tech/sources/posts-on-chris-banes.md>)

Topics: [WebSocket](<https://devfeed.tech/topics/websocket.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [Socket.IO](<https://devfeed.tech/topics/socket-io.md>), [App](<https://devfeed.tech/topics/app.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [servers](<https://devfeed.tech/topics/servers.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Security](<https://devfeed.tech/topics/security.md>), [client](<https://devfeed.tech/topics/client.md>), [Sanitization](<https://devfeed.tech/topics/sanitization.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [app](<https://devfeed.tech/tags/app.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [browser](<https://devfeed.tech/tags/browser.md>), [building](<https://devfeed.tech/tags/building.md>), [code](<https://devfeed.tech/tags/code.md>), [node](<https://devfeed.tech/tags/node.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [websocket](<https://devfeed.tech/tags/websocket.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This tutorial explains how to build a real-time chat application with WebSockets and Socket.IO. It covers the two-way browser-server connection, a basic Node.js server that broadcasts chat messages, client-side message handling, and security considerations including input sanitization, authentication, authorization, and XSS prevention.

### Source excerpt

Have you ever wished your online chats felt more like actual conversations, without needing to constantly refresh the page for new messages? If so, WebSockets are the answer! WebSockets let you build real-time chat apps where messages flow instantly. Unlike regular websites, WebSockets keep a connection open between your app and the server. That means [...]

## 7 tips to become a successful bug bounty hunter

DevFeed: [7 tips to become a successful bug bounty hunter](<https://devfeed.tech/articles/7-tips-to-become-a-successful-bug-bounty-hunter-7780.md>)

Original publisher: [Read original article](<https://snyk.io/blog/7-tips-to-become-bug-bounty-hunter/>)

Author: Ben Sadeghipour

Published: 2024-01-25T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [ambassador](<https://devfeed.tech/tags/ambassador.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [sql](<https://devfeed.tech/tags/sql.md>), [tech](<https://devfeed.tech/tags/tech.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-disclosure](<https://devfeed.tech/tags/vulnerability-disclosure.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This article explains bug bounty hunting, including how security researchers identify and responsibly report vulnerabilities in web applications, IoT devices, mobile applications, and smart contracts. It distinguishes vulnerability disclosure programs from bug bounty programs and recommends that beginners start with a Vulnerability Disclosure Program before pursuing paid bug bounties.

### Source excerpt

In this post, we'll cover what bug bounty hunting is, the difference between vulnerability disclosure programs and bug bounty programs, and seven tips to get you started.

## Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195)

DevFeed: [Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195)](<https://devfeed.tech/articles/understanding-and-mitigating-the-jinja2-xss-vulnerability-cve-2024-22195-7992.md>)

Original publisher: [Read original article](<https://snyk.io/blog/jinja2-xss-vulnerability/>)

Author: Liran Tal

Published: 2024-01-18T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Python](<https://devfeed.tech/topics/python.md>), [Library](<https://devfeed.tech/topics/library.md>), [Scripting](<https://devfeed.tech/topics/scripting.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [python](<https://devfeed.tech/tags/python.md>), [python-dependencies](<https://devfeed.tech/tags/python-dependencies.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This article explains the Jinja2 cross-site scripting vulnerability CVE-2024-22195, which affects versions before 3.1.3. It describes the vulnerable filter behavior, the potential for injecting arbitrary HTML attributes and executing untrusted scripts in a browser, and ways to check project dependencies and scan them with Snyk.

### Source excerpt

On January 11th, 2024, a significant security vulnerability was disclosed in Jinja2, a widely used Python templating library. Identified as CVE-2024-22195, this cross-site scripting (XSS) vulnerability has raised concerns due to its impact on numerous projects.

## Mitigating DOM clobbering attacks in JavaScript

DevFeed: [Mitigating DOM clobbering attacks in JavaScript](<https://devfeed.tech/articles/mitigating-dom-clobbering-attacks-in-javascript-8017.md>)

Original publisher: [Read original article](<https://snyk.io/blog/mitigating-dom-clobbering-attacks-javascript/>)

Author: Keshav Malik

Published: 2023-08-07T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Document Object Model (DOM)](<https://devfeed.tech/topics/dom.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [HTML](<https://devfeed.tech/topics/html.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [browser](<https://devfeed.tech/tags/browser.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [html](<https://devfeed.tech/tags/html.md>), [html-elements](<https://devfeed.tech/tags/html-elements.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [time](<https://devfeed.tech/tags/time.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This article explains DOM clobbering, a condition in which HTML element IDs or name attributes conflict with global JavaScript variables or functions. It describes how browsers create global variables from these attributes, how conflicts can overwrite existing functions, and how attackers may exploit the behavior to cause unpredictable behavior or security vulnerabilities such as cross-site scripting (XSS).

### Source excerpt

This article explores the concept of DOM clobbering and provides strategies for building more secure and robust web applications.

## Astro 0.23 Release Notes

DevFeed: [Astro 0.23 Release Notes](<https://devfeed.tech/articles/astro-0-23-release-notes-3139.md>)

Original publisher: [Read original article](<https://astro.build/blog/astro-023/>)

Author: Fred Schott

Published: 2022-02-19T00:00:00Z

Content type: release

Language: en

Sources: [The Astro Blog](<https://devfeed.tech/sources/the-astro-blog.md>)

Topics: [Astro](<https://devfeed.tech/topics/astro.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [HTML](<https://devfeed.tech/topics/html.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [TypeScript](<https://devfeed.tech/topics/typescript.md>), [Vite](<https://devfeed.tech/topics/vite.md>), [JSON](<https://devfeed.tech/topics/json.md>), [XML](<https://devfeed.tech/topics/xml.md>)

Tags: [astro](<https://devfeed.tech/tags/astro.md>), [browser](<https://devfeed.tech/tags/browser.md>), [code](<https://devfeed.tech/tags/code.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [html](<https://devfeed.tech/tags/html.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [json](<https://devfeed.tech/tags/json.md>), [release](<https://devfeed.tech/tags/release.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [security](<https://devfeed.tech/tags/security.md>), [typescript](<https://devfeed.tech/tags/typescript.md>), [vite](<https://devfeed.tech/tags/vite.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Astro v0.23.0 introduces dynamic file routes for generating JSON, XML, and non-text assets such as images during builds. The release also begins automatic HTML escaping for template expressions to reduce XSS risks, adds directives for controlled HTML and text insertion, and updates access to sensitive environment variables. The article highlights Vite 2.8 among the release changes.

### Source excerpt

Introducing: Dynamic file routes - Automatic XSS protection - two new component directives - vite 2.8 - and more!

## Node.js 16.6.2 (Current)

DevFeed: [Node.js 16.6.2 (Current)](<https://devfeed.tech/articles/node-js-16-6-2-current-2631.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v16.6.2>)

Published: 2021-08-11T16:42:12Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>)

Tags: [dns](<https://devfeed.tech/tags/dns.md>), [memory](<https://devfeed.tech/tags/memory.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [release](<https://devfeed.tech/tags/release.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Node.js 16.6.2 is a security-focused current release that addresses hostname validation issues in the DNS library, a use-after-free vulnerability in HTTP/2 stream cancellation, and incomplete validation of the HTTPS rejectUnauthorized parameter. It also includes dependency, HTTP/2, TLS, and c-ares updates.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Node.js 14.17.5 (LTS)

DevFeed: [Node.js 14.17.5 (LTS)](<https://devfeed.tech/articles/node-js-14-17-5-lts-2557.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v14.17.5>)

Published: 2021-08-11T16:41:40Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [command-line](<https://devfeed.tech/tags/command-line.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [lts](<https://devfeed.tech/tags/lts.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Node.js 14.17.5 is an LTS security release addressing vulnerabilities in DNS hostname handling, HTTP/2 stream cancellation, and HTTPS certificate validation.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Node.js 12.22.5 (LTS)

DevFeed: [Node.js 12.22.5 (LTS)](<https://devfeed.tech/articles/node-js-12-22-5-lts-2503.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v12.22.5>)

Published: 2021-08-11T16:41:05Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>)

Tags: [dns](<https://devfeed.tech/tags/dns.md>), [lts](<https://devfeed.tech/tags/lts.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [release](<https://devfeed.tech/tags/release.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

Node.js 12.22.5 is an LTS release that addresses security vulnerabilities in the DNS, HTTP/2, and HTTPS functionality. It includes fixes for hostname validation, a use-after-free issue during HTTP/2 stream cancellation, and incomplete validation of the rejectUnauthorized parameter, along with dependency updates and additional tests.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Cross-Origin Web Sessions

DevFeed: [Cross-Origin Web Sessions](<https://devfeed.tech/articles/cross-origin-web-sessions-29957.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/web-session-sharing-transfer/>)

Author: info@goteleport.com (Russell Jones)

Published: 2021-05-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Web](<https://devfeed.tech/topics/web.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Cookies](<https://devfeed.tech/topics/cookies.md>), [Security](<https://devfeed.tech/topics/security.md>), [XSS](<https://devfeed.tech/topics/xss.md>)

Tags: [cookies](<https://devfeed.tech/tags/cookies.md>), [http](<https://devfeed.tech/tags/http.md>), [request](<https://devfeed.tech/tags/request.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This article examines mechanisms for securely transferring user sessions between web applications hosted on different domains. It explains browser cookies, session tokens, domain limitations, and query parameters as one approach for cross-origin session sharing.

### Source excerpt

Russell examines the available mechanisms for securely transferring user sessions across different web applications running at different domains.

## CSRF Attacks: Examples and Mitigations

DevFeed: [CSRF Attacks: Examples and Mitigations](<https://devfeed.tech/articles/what-is-a-csrf-attack-and-what-are-the-mitigation-examples-29615.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/csrf-attacks/>)

Author: info@goteleport.com (Russell Jones)

Published: 2021-03-25T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Cookies](<https://devfeed.tech/topics/cookies.md>), [HTML](<https://devfeed.tech/topics/html.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [browser](<https://devfeed.tech/tags/browser.md>), [code](<https://devfeed.tech/tags/code.md>), [cookies](<https://devfeed.tech/tags/cookies.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [html](<https://devfeed.tech/tags/html.md>), [http](<https://devfeed.tech/tags/http.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This tutorial explains how Cross-Site Request Forgery (CSRF) attacks use browsers, HTML elements, cookies, and ambient credentials to submit requests as a logged-in user. It presents examples of state-changing requests and discusses their security impact and mitigations.

### Source excerpt

Understanding Cross-Site Request Forgery (CSRF) and its Mitigations.

[Next page](<https://devfeed.tech/tags/xss.md?cursor=WyIyMDIxLTAzLTI1VDAwOjAwOjAwKzAwOjAwIiwgIjFlM2QzYzNlLWFjNTctNDQyOS05OGIxLWUxNDdlYjliOWMwYyJd>)