Using form hijacking to bypass CSP
portswigger.net | research | #burp-suite | #web-security | #password-managers | #csp | #bypass | #form-hijacking
Summary
Form hijacking bypasses CSP via injected forms or formaction attributes while password managers auto-fill credentials. Seen on Infosec Mastodon and PortSwigger's site; Burp added passive scan checks.
- Published
- Collected
Skip to content