Threat CC.AuC.DFsXSS.3
URI: CC.AuC.DFsXSS.3
Package: VulnerabilityCVSS
< prev | next >
Description: Stored XSS exploit against Client by Service injected via input Data from FlowsFrom: an attacker who can inject malicious content into input Data flowing to Service from FlowsFrom can exploit a bug in Service, and send a harmful script to a trusting client browser Client. We assume this will make the browser leak authentication credentials, such as a password or session key.
Threat Type: Primary Threat