AevoA
Aevo
17h ago

Potential Cross-Site Scripting Payload

<img src=x onerror=alert(1)>
ClosedClosed

changed status toClosed·13 hours ago
13 hours ago

there should be no place in the app where HTML is accepted and therefore not run. Where needed it will escape syntax properly.

changed status toReviewing·13 hours ago