Skip to content
This repository has been archived by the owner on Aug 14, 2020. It is now read-only.

XSS Vulnerability via remote Feeds #10

Open
splitbrain opened this issue Apr 12, 2016 · 0 comments
Open

XSS Vulnerability via remote Feeds #10

splitbrain opened this issue Apr 12, 2016 · 0 comments

Comments

@splitbrain
Copy link

The stripHTML feature of lastRSS is not used thus a malicious feed could inject arbitrary JavaScript into the output. HTML should only be allowed if the htmlok option of DokuWiki is enabled.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant