Site icon API Security Blog

Cross site scripting in github.com/tiagorlampert/CHAOS

A malicious actor may be able to extract a JWT token via malicious "/command" request. This is a form of cross site scripting…Read More

Exit mobile version