Hacker News new | ask | show | jobs
by kaba0 1795 days ago
If an attacker could inject anything into the page, they may as well rewrite the form’s target URL, so I don’t see a real threat model for that.