3 ms·
Supporting HTML in the description makes XSS more likely: https://provetheywantit.com/project?public_token=pub_KSUPBwlYYYevfIdgAmxiIsGqXPledKwqfbNN https://pro
by daltonlp 6y ago
Supporting HTML in the description makes XSS more likely:
https://provetheywantit.com/project?public_token=pub_KSUPBwlYYYevfIdgAmxiIsGqXPledKwqfbNN https://provetheywantit.com/project?public_token=pub_KSUPBwl...
- repartix 6y agoDoes XSS in the description hurt? There's nothing to steal from the /project page and it's not displayed in /admin.
- withinboredom 6y agoDo you really want someone to inject some js that says "click here to receive notifications about this project" that actually sends them spam notifications?
- repartix 6y agoFixed, thanks! Also urls get hyperlinked now.