alexjoverm / alexjoverm/v-runtime-template
Vulnerable to XSS/script injection
Abierto
- Lenguaje dominante
- JavaScript
- Estrellas
- 601
- Forks
- 71
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
Simply setting a string to the following:
`alert('arf, arf. Gotcha!');`
and voila, your template will render it, script intact, resulting in the script running.
Needless to say this is incredibly dangerous.
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Evaluación
Este issue todavía no se ha evaluado.