3 ms·
But if the scenario is an attacker who can inject HTML tags, why wouldn't they simply run their script directly via <script>do_evil();</script>?
by moe 11y ago
But if the scenario is an attacker who can inject HTML tags, why wouldn't they simply run their script directly via <script>do_evil();</script>?
- pauljohncleary 11y agoBecause a properly configured content security policy will block any inlined js (and external js files on non whitelisted domains)