Hi everyone, I recently spent some time looking at browser parsing differences around malformed HTML, MathML and sanitizers. I was not specifically hunting for a DOMPurify issue when I started. I had a few small parser test cases, I was […]
Tag: html
Vtiger CRM v8.2.0 – HTML Injection (Authenticated)
#Exploit Title: Vtiger CRM v8.2.0 – HTML Injection (Authenticated) #Date: 12 September 2024 #Exploit Author: Okan Kurtulus #Vendor Homepage: https://www.vtiger.com #Version: v8.2.0 #Tested on: Ubuntu 22.04 #CVE: 2024-48119 Proof of Concept: After logging in as a registered user, it was […]


