← Back to feed
research PortSwigger Research

Inline Style Exfiltration: leaking data with chained CSS conditionals

PortSwigger Research

I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes!

T1041
Read the full story PortSwigger Research →

Related Coverage

research 24th August – Threat Intelligence Report Check Point Research · Aug 24 research How a team of entity maintainers monitors, connects and scores entities in Elastic Security Elastic Security Labs · Aug 24 research Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 · Aug 21