4 ms·
The google document being used talks about crossing an origin-boundary. So website with bad script injected is loaded by the user and is able to make requests
by amsully 7y ago
The google document being used talks about crossing an origin-boundary.
So website with bad script injected is loaded by the user and is able to make requests to a logged-in banking website with time-based/scrolling attacks.