Skip to content

A xss on the newest version #3007

@fr4nk404

Description

@fr4nk404

Issuehunt badges

XSS

There is a xss in the newest version via a label named mermaid
When we insert codes like this:

graph LR
id1["<iframe src=javascript:alert('xss')></iframe>"]
Loading

we can see there is a xss in the latest version.
image


IssueHunt Summary

amedora amedora has been rewarded.

Backers (Total: $40.00)

Submitted pull Requests


Tips


IssueHunt has been backed by the following sponsors. Become a sponsor

Metadata

Metadata

Assignees

No one assigned

    Labels

    bug 🐛Issue concerns a bug.funded on issuehunt 💵Issue has received funding that will be rewarded to the contributor solving this issue.rewarded on issuehunt 🎁Issue has been resolved and a contributor has been rewarded.security issue 🔑Issue concerns Boostnote's security. Usually high priority.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions