(no title)
chill1 | 4 years ago
Another reply seems to have focused on having XSS causing an attacker to gain access to session cookies. But no one has mentioned using Content-Security-Policy [0] - which if set properly can make it nearly impossible to exploit an XSS vulnerability in the first place.
eganist|4 years ago
which far, far too many apps do.