1 Matching Annotations
- Apr 2020
-
www.moesif.com www.moesif.com
-
Without same-origin policy, that hacker website could make authenticated malicious AJAX calls to https://examplebank.com/api to POST /withdraw even though the hacker website doesn’t have direct access to the bank’s cookies.
Cross-domain vulnerability
-