Threat CC.AuC.DSrXSS.3
URI: CC.AuC.DSrXSS.3
Package: VulnerabilityCVSS
< prev | next >
Description: Reflected XSS exploit on Client from Service injected via locally stored client input Data: an attacker who can inject malicious content into locally stored input Data used by Client can exploit a bug in Service and send a harmful script to the client browser. We assume this will make the browser leak authentication credentials, such as a password or session key.
Threat Type: Primary Threat