|
|
|
|
|
by dsacco
4086 days ago
|
|
This is a cross-site scripting vulnerability, yes, but client-side crypto does not necessitate cross-site scripting. This implementation just so happens to not protect against it properly. There are legitimate arguments against client-side cryptography; this is not one of them. |
|
[1] your browser