logo

DOJO CHALLENGE #7 Winners!

ID: de531c24-6e76-5d9c-9a5c-bf89e2dc6efa

STIX ID: report--de531c24-6e76-5d9c-9a5c-bf89e2dc6efa

Feed Name: YesWeHack Blog

Threat Score
45/100

Date Published: 2021-03-12

Date Updated: 2026-07-04

...
...

This write-up documents a web application vulnerability and exploit: a WAF bypass using JavaScript prototype pollution ("__proto__": []) to inherit Array methods and circumvent forbidden-character checks, enabling a reflected XSS; a PoC payload and remediation advice (use instanceof and DOMPurify) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.