Threat CC.AuC.DFrXSS.3
URI: CC.AuC.DFrXSS.3
Package: VulnerabilityCVSS
< prev | next >
Description: Reflected XSS exploit on Client via Service injected via client input Data from FlowsFrom: an attacker who can inject malicious content into input Data flowing to Client from FlowsFrom can exploit a bug in Service to send a harmful script to the client browser. We assume this will make the browser leak authentication credentials, such as a password or session key.
Threat Type: Primary Threat