Vulnerabilities tagged "smart-contract"

Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library

Three vulns that were discovered in Netlify's Next.js lib, which is heavily used across many cryptocurrency sites due to it's web3 support. With that context in mind, CIA (confidentiality, integrity, availability) is interesting with web3, as integrity is critical; the data coming from a trusted site needs to be trustworthy, as most users won't go digging through the blockchain to verify a particular address or transaction matches.