WhisperX tag archive

#cookie-injection

This page collects WhisperX intelligence signals tagged #cookie-injection. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-13 15:48:34 · GitHub Issues

1. Critical XSS Flaw in Dashboard Controller Exposes Users to Cookie-Based JavaScript Injection via Unescaped Font Parameter

A critical cross-site scripting vulnerability has been identified in the application's dashboard controller, stemming from unsanitized user input persisted through cookies. The flaw allowed attacker-controlled `params[:font]` values to be stored in `cookies[:font]` and subsequently injected—without escaping—into an inl...