3 ms·
I hope you are aware about this attack vector[1] that was fixed in React long time ago. 1. http://danlec.com/blog/xss-via-a-spoofed-react-element http://danlec
by localvoid 8y ago
I hope you are aware about this attack vector[1] that was fixed in React long time ago.
1. http://danlec.com/blog/xss-via-a-spoofed-react-element http://danlec.com/blog/xss-via-a-spoofed-react-element
- toxmeister 8y agoThanks & I wasn't (aware of it). hdom doesn't use `.innerHTML` anywhere, though. So I'd dare to say less dangerous... though not saying it's out of danger!