http://opdz3nfh6n54ndhle4nkcbecn7ozfuowm5c6hlclvhcwndeg3tr5vrqd.onion/125-2/index.html
The first vulnerability, i.e. not having the “ secure ” and “ httponly ” cookie flag enabled, allowed attackers to steal login cookies of a user by injecting a malicious JavaScript into the DJI Forum website using the XSS vulnerability. “ To trigger this XSS attack all the attacker need do is to write a simple post in the DJI forum which would contain the link to the payload, ” the researchers explained in a report published today. “ A user who logged into DJI Forum, then clicked a...