4 ms·
Sorry to bring it up here, but can you check your email for an email from david@daviddworken.com? I previously sent in an XSS vulnerability that you fixed quick
by kolapuriya 10y ago
Sorry to bring it up here, but can you check your email for an email from david@daviddworken.com? I previously sent in an XSS vulnerability that you fixed quickly, but I found a second one that has not been patched yet (despite being reported on March 26th).
- ddworken 10y agoThanks for reposting that comment here (I posted it on /r/python). I'm now in contact with him and I'll update this once it has been fixed.
- ddworken 10y agoIt has now been fixed. The problem stemmed from allowing the `Javascript:` scheme for the home_page, download_url, and the url parameters in the setup.py.