Mutation XSS (mXSS) and DOM Clobbering: Exploitations and Security Best Practices
Allowing users to insert HTML content is a common feature in web applications. WYSIWYG editors, commenting systems, messaging services, CMSs and collaborative tools often need to allow the use of rich text whilst preventing the execution of arbitrary JavaScript code.…