3 ms·
Yeah if an attacker was able to insert javascript then it's possible.
by ronnier 1y ago
Yeah if an attacker was able to insert javascript then it's possible.
- blr_lpm 1y agoFor this particular threat vector, where the client is compromised, the backend doesn’t matter.
- franga2000 1y agoA compromised server can inject exfil code into the web page it serves. If you only ever use the apps then you should be fine though.
- 9cb14c1ec0 1y agoWhich is only possible if logging into the web client and not when using the bitwarden desktop app or browser extensions.