What’s the worst that can happen with reflected XSS?

I’ve found an issue in a web app where I can use a parameter in the url for reflected XSS. But I don’t know how big of an issue is it?

I want to know so I can cash on the report in the same way.

submitted by /u/andenate08
[link] [comments]

from hacking: security in practice https://ift.tt/3BPNR84

Comments