We could still demonstrate the XSS attack by making is stored in cookies. This would allow to add XSRF attack as well.