Yep, it's another instance of the same false positive this thread is about.Castle Freak wrote: ↑Tue Jul 25, 2023 7:58 pm Hey again!
I just provoked the NoScript Warning again. This is what i got:
[...]
Any idea?
Since you didn't censor any of the parameters at all, and I believe some of them maybe sensitive personal information, I've hidden your post. And with the information in the now-hidden post, I'm now pretty sure the "paymentInstrumentId" parameter I couldn't evaluate earlier is not XSS.
In case the suggested workaround got buried, quoting it again -