Decathlon / Decathlon/ara

Sanitize HTML in communications

Open
#54 0 comments 0 reactions 0 assignees View on GitHub
bug good first issue hacktoberfest P3
Dominant language
Java
Stars
80
Forks
17
PR merge metrics
No merged PRs in 30d

Description

Users can set HTML content on communications. There is a security risk of script being added by malicious users.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by locating where communications HTML is accepted and rendered, then trace how user-supplied content reaches the output. Done means malicious script content is sanitized and the behavior is covered by a regression test.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
backend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
40/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.