Post cover image

June 11, 2026

Chaining Stored XSS and CSRF in Typemill CMS: A Deep Dive into Attribute Injection

How I bypassed frontend validation to inject malicious scripts into page metadata and steal admin sessions.

Sandiyo Christan

3 min read