Stealing passwords from infosec Mastodon - without bypassing CSP
Stealing passwords from infosec Mastodon - without bypassing CSP

portswigger.net
Stealing passwords from infosec Mastodon - without bypassing CSP

cross-posted from: https://community.hackliberty.org/post/9544
The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP.