Web Hack List

Collected research

Exploiting POST-based XSSI

A service worker on the attacker's own page intercepts its own script include and reissues it as a credentialed cross-origin POST with a safelisted content type. Any endpoint that answers a POST with valid JavaScript then leaks its contents to the including page, extending cross-site script inclusion beyond GET requests.

Record

Researcher
@1lastBr3ath and Prakash
Published by
DON'T BE A 5KIDDO, BE A HACKER
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @1lastBr3ath and Prakash, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .