Hacker News new | ask | show | jobs
by amsully 2309 days ago
The google document being used talks about crossing an origin-boundary.

So website with bad script injected is loaded by the user and is able to make requests to a logged-in banking website with time-based/scrolling attacks.