Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Theoretically the xss could become a non-self xss if the conversation is stored and replayed back and that application has the xss vulnerability e.g. if the conversation is forwarded to a live agent.

A lot of unproven Ifs there though.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: