3DSecure 2.0 3DS Method Authentication Cross Site Scripting

Discussion in 'News Aggregator' started by Packet Storm, 13 Sep 2024.

  1. Packet Storm

    Packet Storm Guest

    3DSecure version 2.0 is vulnerable to cross site scripting in its 3DSMethod Authentication. This vulnerability allows remote attackers to hijack the form action and change the destination website via the params parameter, which is base64 encoded and improperly sanitized.

    Continue reading...
     

Share This Page

Loading...