Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5197XSS without HTML: Client-Side Template Injection with AngularJS CSTI XSS Google Gareth Heyes (@garethheyes) Bug Bounty2016-01-272023-06-13
4892Reflected XSS via AngularJS Template Injection Reflected XSS CSTI Hostinger Taha Ibrahim Draidia Bug Bounty2018-01-172023-06-13
3534The Secret sauce of bug bounty CSTI Stored XSS CORS misconfiguration NA Mohamed Slamat (@oxxy37) Bug Bounty2020-04-222023-06-13
3507Reflected XSS on Microsoft.com via Angular Js template injection CSTI XSS Microsoft Pratik Dabhi (@impratikdabhi) Bug Bounty2020-05-022023-06-13
2981"Important, Spoofing" - zero-click, wormable, cross-platform remote code execution in Microsoft Teams RCE Stored XSS CSP bypass CSTI Microsoft Oskars Vegeris Bug Bounty2020-12-072023-06-13
2740Leveraging Template injection to takeover an account. CSTI XSS NA Akash Methani (@0xAkash) Bug Bounty2021-03-042023-06-13
2638How I earned $$$$ through Stored XSS Stored XSS CSTI NA Harish Bug Bounty2021-04-162023-06-13
2519The beauty of chaining client-side bugs CRLF injection XSS CSP bypass DoS CSTI NA Master SEC (@MasterSEC_AR) Bug Bounty2021-05-292023-06-13
2507XSS in the AWS Console XSS CSP bypass CSTI AWS Nick Frichette (@frichette_n) Bug Bounty2021-06-022023-06-13
2072Finding Zero-Day Vulnerabilities in the Supply Chain CSTI Signature bypass Adaxes Roni Carta (@0xLupin) Bug Bounty2021-11-162023-06-13
1923C.S.T.I Lead To Account Takeover $$$ CSTI Account takeover NA M7.Arman (@ArmanSecurity) Bug Bounty2022-01-132023-06-13
1495An unusual way to find XSS injection in one minute CSTI XSS TimeWeb Andrey Onishchenko Bug Bounty2022-06-072023-06-13
1228XSS via Angular Template Injection CSTI XSS WAF bypass NA Bartłomiej Bergier (@_bergee_) Bug Bounty2022-08-132023-06-13
1142AngularJS Client-Side Template Injection: The orderBy Filter. CSTI NA Jay Bug Bounty2022-09-012023-06-13
1035Stored XSS in Nvidia via Angular JS template injection CSTI Stored XSS Nvidia Mohamed Abdelhady Bug Bounty2022-09-252023-06-13
934FabriXss (CVE-2022-35829): How We Managed to Abuse a Custom Role User Using CSTI and Stored XSS in Azure Fabric Explorer CSTI Stored XSS Microsoft Lidor Ben Shitrit Bug Bounty2022-10-192023-06-13
185Popping Tags: Exploiting Template Injections in PRTG Network Monitor Reflected XSS CSTI Paessler Peter Szot Bug Bounty2023-04-182023-06-13