Nice to read text on a clever find.
Could somebody please confirm or invalidate my understanding, that this backdoor is just exploitable in addition with other (severe) issues?
An attacker would have to have the ability to tailor/manipulate JS scripts which should be under control of the victim?
Or am i mistaken?