Post
Topic
Board Reputation
Re: [ CWE-79 ] *.nastyfans.org is vulnerable to script injection
by
suchmoon
on 18/06/2020, 18:08:06 UTC
It seems that I lack knowledge about this, can you explain it more clearly? How can that be? Something called coerce? It is really difficult to force someone to do what the attacker wants, unless they have tricks to cover the user's eyes. Right?  Roll Eyes

It's all explained in great detail here.

This still depends on whether and how the same-origin-policy is implemented.

True. It's not quite as simple as I made it sound.