Other nomination
XSS in GMAIL Dynamic Email
Gmail's AMP for Email sanitizer could be escaped from inside a style amp-custom block: the parser acted on an unterminated closing style tag and auto-generated closing tags, letting injected markup break into the document body. Only a meta refresh survived the tag filter, navigating the mail view to a data URL; Gmail's CSP blocked script execution. Google paid a 6,000 dollar bounty.
Record
- Researcher
- asdqw3
- Published by
- Medium
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of asdqw3, first published at the original source. Preserved copies are kept so the citation survives its host.