ScaleSec/vulnado

JWT is held in local storage

jeger opened this issue · 0 comments

jeger commented

We could still demonstrate the XSS attack by making is stored in cookies. This would allow to add XSRF attack as well.