Web Hack List

Collected research

Formaction Scriptless attack updates

#HackerKast 29 Bonus Round: Formaction Scriptless Attack

Even with a strict Content Security Policy blocking script, an HTML injection can add an input element that joins an existing form by id and overrides its target with formaction, aiming the submission at the attacker. Framing the page and steering the victim into clicking the button hands over the form's CSRF nonce, letting the attacker forge the request without any JavaScript.

Record

Document
#HackerKast 29 Bonus Round: Formaction Scriptless Attack
Published by
WhiteHat Security
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of WhiteHat Security, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .