Update README.MD

This commit is contained in:
nu11secur1ty 2023-07-07 10:26:03 +03:00 committed by GitHub
commit c89dac4d05
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -7,8 +7,9 @@
## Description:
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is data inside the targeted website like IDs, tokens, nonces, cookies, IP, User-Agent, and other sensitive information.
The user would have to click on a specially crafted URL to be compromised by the attacker.
In this example, the attacker use `STRIDE Threat Modeling` to spoof the victim to click on his website and done.
This will be hard to detect.
In this example, the attacker uses `STRIDE Threat Modeling` to spoof the victim to click on his website and done.
This is the general spoofing vulnerability and does not cover only EDGE, all browsers can be manipulated this way
on every OS. This will be hard to detect.
## Conclusion:
Please be careful, for suspicious sites or be careful who sending you an link to open!