4 ms·
I could see this being an issue on sites that allow custom css (reddit)
by moojd 9y ago
I could see this being an issue on sites that allow custom css (reddit)
- fareesh 9y agoThe combination of the two prerequisite conditions is probably tiny. JS needs to update the css accessible value attribute of the field as well. That's a less likely situation. I guess anything that's react + this auth method + custom CSS is vulnerable. Can't think of anything that does all three.