Simple Data Exfiltration Through XSS
ID: 0ac87c67-38c3-50f6-af1c-af7d5b9b817a
STIX ID: report--0ac87c67-38c3-50f6-af1c-af7d5b9b817a
Feed Name: TrustedSec blog
This blog post documents a stored XSS vulnerability in a document management app and a step-by-step proof-of-concept for data exfiltration: the injected script loads a remote payload, uses the victim's privileged session to fetch a sensitive page, base64-encodes and splits the content into filename-sized chunks, then exfiltrates those chunks via repeated requests for non-existent image/JS filenames to an attacker server; the author also describes server-side capture and reconstruction commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
