CSS injection: what's the worst that can happen?

前端 未结 1 993
执笔经年
执笔经年 2020-12-28 15:37

We are doing a security evaluation.

There is a chance that a malicious user can inject arbitrary CSS into another user\'s web pages, although we are not sure it can

相关标签:
1条回答
  • 2020-12-28 16:06

    Yes to all of the above. Injection of arbitrary CSS can lead to javascript execution. Look at:

    • XSS Cheat Sheet

    The worst thing that could happen is dependent on the environment. In some cases stealing a session cookie and accessing the users session maybe the worst thing to happen (e.g., banks, online stock trading) this may not be the case for your situation. Other examples of attacks would be gaining control of the browser, gaining access to the client's machine, etc.

    0 讨论(0)
提交回复
热议问题