cross-frame-scripting

1 article
sort: new top best
clear filter
0 6/10

A CSRF protection bypass achieved by chaining cross-frame scripting (XFS) with CSRF exploitation, where an attacker removes the CSRF token from a PoC, triggers a server response that includes a valid token, then embeds this within a clickjacking attack to auto-submit forms with attacker-controlled values.

HackerOne Burp Suite
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details