The first vulnerability, i.e. not having the “ secure ” and “ httponly ” cookie flag enabled, allowed attackers to steal login cookies of a user by injecting a malicious JavaScript into the DJI Forum website using the XSS vulnerability. “ To trigger this XSS attack all the attacker need do is to write a simple post in the DJI forum which would contain the link to the payload, ” the researchers explained in a report published today. “ A user who logged into DJI Forum, then...