Expected behavior
XSS filter evasion should cover each edge case. All possible XSS code should be rejected.
Actual behavior
XSS filter evasion is not working for input text method, DIV expression method, and WAF ByPass Strings for XSS.
How to reproduce
Here are all the urls you can test to reflect the XSS bug:
https://gist.github.com/jayserdny/bf23a88197aabe2cbc5bae96fc31a198
Environment
- Browser: Google Chrome Version 64.0.3282.186 (Official Build) (64-bit)
- Operating system: macOS High Sierra
Some screenshots of the bug
Posted on Utopian.io - Rewarding Open Source Contributors