Exploiting XSS in POST requests
portswigger.net | vulnerability | #web-security | #xss | #portswigger | #csrf | #reflected-xss | #post-requests | #form-submission
Summary
Reflected XSS reachable only via POST is exploitable: an attacker page auto-submits a crafted form cross-domain, CSRF-style, and the payload runs inside the vulnerable application's security context.
- Published
- Collected
Skip to content