Bidding Like a Billionaire - Stealing NFTs With 4-Char CSTIs
0 net
A story about an incredibly impactful XSS vulnerability I found using a client side template injection which was limited to 4 characters.