What MITRE CAPEC-111: JSON Hijacking (aka JavaScript Hijacking) (Standard Attack Pattern - High Severity) requires
MITRE CAPEC-111 (JSON Hijacking (aka JavaScript Hijacking)) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker targets a system that uses JavaScript Object Notation (JSON) as a transport mechanism between the client and the server (common in Web 2.0 systems using AJAX) to steal possibly confidential information transmitted from the server back to the client inside the JSON object by taking advantage of the loophole in the browser's Same Origin Policy that does not prohibit JavaScript from one website to be. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-345, CWE-346, CWE-352.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/111.html
SHA-256 integrity: bfc1e9e816577809d9e0832dadd311e4272505112be5c6bf3ff131c81c9659f9
Primary Citations — 9 traced to source
- MITRE CAPEC-111: JSON Hijacking (aka JavaScript Hijacking) (https://capec.mitre.org/data/definitions/111.html)
- CWE-345: underlying weakness (http://cwe.mitre.org/data/definitions/345.html)
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-capec-capec-111-json-hijacking-aka-javascript-hijacking.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-capec-capec-111-json-hijacking-aka-javascript-hijacking.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-capec-capec-111-json-hijacking-aka-javascript-hijacking
- Back to registry: Browse all 10,085 compliance nodes