articlesמקור: PortSwigger Research6.8.2026
CSS: פצצה בדואר הנכנס שלך
CSS:the bomb inside your inbox

◆ סיכום AI
לקוחות דואר אלקטרוני רבים נוטים לרנדר קוד CSS לא מהימן בממשק משתמש מהימן. הם מנסים לאבטח זאת באמצעות סניטציה של CSS. עם זאת, גישה זו עלולה להוביל לפרצות אבטחה אם תהליך הסניטציה אינו מושלם ומאפשר הזרקת קוד זדוני.
# מהמקור
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
#css#webmail#sanitization#vulnerability
קרא במקור