4 ms·
an attacker could use css to cover a login input and button with their own elements. Without html injection just think about what might be done to disrupt a si
by vimax 5y ago
an attacker could use css to cover a login input and button with their own elements.
Without html injection just think about what might be done to disrupt a site. Here on HN you could swap the comments and hide or flag links and make the site unusable. If it were on a page with a delete link or a close account link, you could trick someone into irrecoverable data loss.
Thinking only about key loggers is very narrow thinking.
- deleted 5y ago[deleted]