4 ms·
That's a well researched problem, and is common in most JavaScript frameworks. In practice it makes it harder to protect applications using them against XSS.
by koto1sa 9y ago
That's a well researched problem, and is common in most JavaScript frameworks. In practice it makes it harder to protect applications using them against XSS.
Check https://www.slideshare.net/mobile/x00mario/jsmvcomfg-to-sternly-look-at-javascript-mvc-and-templating-frameworks https://www.slideshare.net/mobile/x00mario/jsmvcomfg-to-ster... or script gadgets research https://github.com/google/security-research-pocs/blob/master/script-gadgets/README.md https://github.com/google/security-research-pocs/blob/master... for more complete overview of the issue.
Disclaimer: I'm one of the authors.
- ghusbands 9y agoI made the effort of reading those links to save others the effort. Neither of them are relevant to the vulnerability in the article.