Collected research
Formaction Scriptless attack updates
#HackerKast 29 Bonus Round: Formaction Scriptless Attack
Even with a strict Content Security Policy blocking script, an HTML injection can add an input element that joins an existing form by id and overrides its target with formaction, aiming the submission at the attacker. Framing the page and steering the victim into clicking the button hands over the form's CSRF nonce, letting the attacker forge the request without any JavaScript.
Record
- Document
- #HackerKast 29 Bonus Round: Formaction Scriptless Attack
- Published by
- WhiteHat Security
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of WhiteHat Security, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .