
Proof-of-concept exploit per CVE-2022-29361, che dimostra il desync lato client verso XSS in Werkzeug. Testato su Chromium.
Crediti a @kevin-mizu
https://github.com/kevin-mizu/Werkzeug-CVE-2022-29361-PoC/tree/main
per i dettagli leggi: https://mizu.re/post/abusing-client-side-desync-on-werkzeug
Testato su Chromium 119.0.6045.123 compilato su Debian trixie/sid, in esecuzione su Debian kali-rolling