A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.
Ppmap now supports enumeration for location.hash
pollution
The new version of ppmap (v1.1.4) can detect and exploit more gadgets:
The new version of ppmap (v1.1.3) can detect and exploit more gadgets:
Small typo fixes
The new version of ppmap (v1.1.2) can detect and exploit more gadgets: