3 ms·
> but this still allows arbitrary markup to the page (even <style> CSS rules) if I'm reading the docs correctly. If that's true, seems like it's still a securi
by byproxy 7mo ago
> but this still allows arbitrary markup to the page (even <style> CSS rules) if I'm reading the docs correctly.
If that's true, seems like it's still a security risk given what you can do with CSS these days: https://news.ycombinator.com/item?id=47132102 https://news.ycombinator.com/item?id=47132102
- circuit10 7mo agoYou can use selectors to gain some information about things like input fields, e.g. https://www.invicti.com/blog/web-security/private-data-stolen-exploiting-css-injection https://www.invicti.com/blog/web-security/private-data-stole... Or I guess you could completely restyle and change the text of UI elements so it looks like the user is doing one thing when they're actually doing something completely different like sending you money
- qingcharles 7mo agoBack in 2002 (?) I got banned from a certain auction site because I managed to inject HTML into my username that made it so once I had bid the "Bid" button disappeared for all subsequent users.