-
-
Notifications
You must be signed in to change notification settings - Fork 290
Closed
Milestone
Description
Hi there,
It seems possible to inject XSS directly on domain records like TXT on the data field. This kind of vulnerability has already been reported on who.is service : https://news.ycombinator.com/item?id=8336025
Edit : it seems that filtering is done after saving changes but not before.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels