Origin of this page:
Target: POST https://api.hot.co.il/api/website/2.0/getUserDatA/
If the target reflects this origin + allows credentials, the victim's lgau
cookie is sent, the response is readable by this page, and the data below is exfiltrated
cross-origin.
Awaiting run…