logoalt Hacker News

Andyslast Sunday at 11:15 PM1 replyview on HN

Imagine viewing the same chat logs, while logged in an admin interface, then it isn't self-XSS anymore.


Replies

croemerlast Monday at 12:18 AM

Indeed, it appears that the limited scope meant the juicy stuff could not be tested. Like exfiltrating other users' data.

show 1 reply