Smuggling Through the Front Door... Achieving 0-Click XSS with Cache Poisoning
In this post, I want to walk through how a surviving Azure Front Door desync poisoned platform error pages into a global 0-click XSS. This issue was tracked as VULN-157984, confirmed by Microsoft, fixed, and awarded under the Azure bounty program.