-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Closed
Labels
bug 🐛Issue concerns a bug.Issue concerns a bug.
Description
I'm using the latest version (2018/07/05)
- new notes, select Markdown, write payload:
<img src= "test" onerror=alert ('test') >
It's not going to trigger now.
- when I need to highlight the markdown code, I write it before the code.
" ``` "
I trigger xss. when I enter third.
Boostnote is great!
Metadata
Metadata
Assignees
Labels
bug 🐛Issue concerns a bug.Issue concerns a bug.