logo

Setting the ‘Referer’ Header Using JavaScript

ID: 7f0bf087-1d22-5fdc-9ef2-12ad9f244fac

STIX ID: report--7f0bf087-1d22-5fdc-9ef2-12ad9f244fac

Feed Name: TrustedSec blog

Threat Score
30/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This blog post demonstrates a practical JavaScript technique that fakes the HTTP Referer header by modifying the browser history (pushState/replaceState) before issuing requests, enabling attackers exploiting XSS to make actions appear to come from legitimate pages; it includes example payloads, mitigation notes (limitations such as URL encoding and visible URL change), and links to code and prior related resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.