Security Expert Reaction On Ticktok Patches Reflected XSS Bug That Could Have Been Chained To Hijack Accounts


The two vulnerabilities discovered in the TikTok website, Reflected XSS and CSRF are two commonly known web application risks that are part of the long standing OWASP Top 10 web application security risks. Reflected XSS is part of the Cross Site Scripting (XSS) category of risks and CSRF is part of the Injection category.