Critical Thinking - Bug Bounty Podcast cover image

Episode 168: XSSDoctor - Client-side Path Traversal Research

Critical Thinking - Bug Bounty Podcast

00:00

Capitalization quirk: %252F vs %252f

They reveal React's case-sensitive replace that only decodes uppercase F in %252F, a practical CSPT gotcha.

Play episode from 01:15:54
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app