DOM clobbering TL;DR: Injected HTML id/name attributes overwrite JS global properties used by the app. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://portswigger.net/web-security/dom-based/dom-clobbering