On Jun 16, 2020 a security advisory for Ruby Sanitize library was released about an issue that could lead to complete bypass of the library in its RELAXED config. I have found this bug during a penetration test conducted by Securitum, and in this post I’ll explain how I came up with the idea of ...
The post HTML sanitization bypass in Ruby Sanitize < 5.2.1 appeared first on research.securitum.com.