alexjoverm / alexjoverm/v-runtime-template
Vulnerable to XSS/script injection
オープン
- 主要言語
- JavaScript
- スター
- 601
- フォーク
- 71
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
Simply setting a string to the following:
`alert('arf, arf. Gotcha!');`
and voila, your template will render it, script intact, resulting in the script running.
Needless to say this is incredibly dangerous.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。