Possible injection because of sanitize cache
Aperta
- Lingua principale
- JavaScript
- Stelle
- 814
- Fork
- 37
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
Basically it's possible to inject dirty html:
```js
const striked = 'test';
console.log(
{striked}
);
console.log(
test
);
console.log(
{striked}
);
```
This is the output:
```html
<strike>test</strike>
test
test
```
Expected output:
```html
<strike>test</strike>
test
<strike>test</strike>
```
After rendering `
test
`, it caches `test` and doesn't sanitize it anymore. It can be seen live [here](https://codepen.io/remziatay/pen/YzroqLm?editors=1010) as well. Just because something was rendered before, it shouldn't mean that it's sanitized.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Valutazione
Questa issue non è ancora stata valutata.