-
Notifications
You must be signed in to change notification settings - Fork 22
Closed
Milestone
Description
To trigger the XSS vulnerability, simply paste this into the search bar, e.g. on https://www.scala-lang.org/api/2.12.8/:
"\><img/src='1'onerror=alert(777111)>{{7*7}}
The fix for this is straightforward, PR coming shortly.
All credit for finding the vulnerability goes to Yeasir Arafat:
skylinearafat@gmail.com
https://www.facebook.com/skylinearafat.arafat
Reactions are currently unavailable