logo

XSS Embedded IFrames

ID: c71d2a7f-6354-56cc-9a57-ae79d9a9fb9b

STIX ID: report--c71d2a7f-6354-56cc-9a57-ae79d9a9fb9b

Feed Name: Zscaler Security Research Blog

Threat Score
50/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report describes active cross-site scripting (XSS) vulnerabilities in advertised web pages where hex-encoded HTML in query parameters is rendered unsanitized, enabling injected iframes that redirect visitors to malicious webpages; an encoded payload example and explanation of the issue are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.