4 ms·
There is XSS in the (my-name) part :) (my-name "<img src='#' onerror=alert(1) />")
by qnsoaejacniln 2y ago
There is XSS in the (my-name) part :)
(my-name "<img src='#' onerror=alert(1) />")
- didibus 2y agoNice catch. Is it an issue though when the script injection only runs within your own browser session?
- Jeaye 2y agoNo. That in itself shouldn't be a cause for concern. Local users can do anything to their own machines already. It would be a concern if you persist this to then later be loaded by someono else's machine.
- hpeter 2y agoIt's not XSS if it's not cross-site.