Login
From:
Security Engineering Blog
(Uncensored)
subscribe
Escaping '<' and '>' in attributes – How it helps protect against mutation XSS
https://bughunters.google.com/blog/5038742869770240/escaping-and-in-attributes-how-it-helps-protect-against-mutation-xss
links
backlinks
The HTML specification has been updated to escape '<' and '>' in attributes to prevent mutation XSS (mXSS) vulnerabilities. This post details the reasoning behind this change and explains why this update improves security.
Roast topics
Find topics
Find it!