Leaving HTML unescaped opens up security issues
Open
- Dominant language
- JavaScript
- Stars
- 5k
- Forks
- 454
- PR merge metrics
- No merged PRs in 30d
Description
On http://sharejs.org/wiki/Main you can just enter some mean code like
` location.href='http://google.com'; `
I'm not sure if this is bare ShareJS. Better filter out HTML Code or implement a whitelist known to be harmless.
Editing markdown like this is great by the way.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.