@bug_vs_me
Deepak bug_vs_me
1 year
If you found XSS and in CSP policy unsafe-inline, inline script is disabled and script can be loaded from whitelisted domains "script-src 'self. You can't upload script to current domain, but you see YouTube or google in whitelist domains IN CSP you can use this script below! .
Tweet media one
Tweet media two
3
49
213

Replies

@bug_vs_me
Deepak bug_vs_me
1 year
For YouTube <script src=");"></script> For google :- <script src=""></script> #bugbounty #bugbountytips
3
18
79
@LipinZNT
LipinZNT
1 year
0
1
2
@g0ziem
Goziem
1 year
@bug_vs_me How do we find unsafe inline
2
1
0