By combining OAuth features with an age-old cross-site scripting (XSS) vulnerability, @SaltSecurity researchers were able to take over any account in @hotjar and Business Insider online services. #cybersecurity #infosec #ITsecurity https://t.co/f69cqWApd4
Security Flaws Found in Hotjar, Potentially Affecting Sensitive Data of Millions Utilising Major Global Brands: https://t.co/IFGXnfKA9h by IT Security Guru #infosec #cybersecurity #technology #news
OAuth+XSS Attack Threatens Millions of Web Users With Account Takeover: https://t.co/wORtpmFn2d by darkreading #infosec #cybersecurity #technology #news


Salt Security researchers have identified significant security vulnerabilities in Hotjar and Business Insider that could potentially expose sensitive data of millions of users. The vulnerabilities, which combine OAuth features with a cross-site scripting (XSS) flaw, posed risks of account takeovers and OAuth data risks. These security flaws have since been addressed by Hotjar.