View Single Post
Old 11-25-2015, 02:37 AM  
deonbell
Confirmed User
 
deonbell's Avatar
 
Industry Role:
Join Date: Sep 2015
Posts: 1,045
Quote:
Originally Posted by Ramp View Post
I'd say this is a security hole and needs fixing
Yea, It has been on xssposed.org for a while.

If credentials are stored only on cookies, With the right javascript, Could steal admin cookie and take over admin. Only a possibility. Persistent XSS is much more dangerous than reflective.
deonbell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote