Write-ups
Check The Published Writeups
WDB | Title | Tags | Programs | Authors | Type | Publication | Added |
---|---|---|---|---|---|---|---|
427 | Escaping misconfigured VSCode extensions | Path traversal DNS rebinding XSS HTML injection Webview CSP bypass | Microsoft (SARIF viewer & Live Preview) | Vasco Franco | Bug Bounty | 2023-02-21 | 2023-06-13 |
403 | Escaping well-configured VSCode extensions (for profit) | Electron Webview Path traversal | Microsoft | Vasco Franco | Bug Bounty | 2023-02-23 | 2023-06-13 |