|
|
|
|
|
by miki123211
526 days ago
|
|
You can also console.log those credentials as a PoC, and then show that the console.log could trivially be replaced by a fetch(). Kind of like a lot of exploit PoCs just "pop a calc" (AKA open the Calculator app), not because opening the calculator is valuable to an attacker, but because if you can open calculator, you can do anything. |
|