Skip to content

Another trigger position of XSS #2184

@fungo1024

Description

@fungo1024

I'm using the latest version (2018/07/05)

  1. new notes, select Markdown, write payload:

<img src= "test" onerror=alert ('test') >

It's not going to trigger now.

  1. when I need to highlight the markdown code, I write it before the code.

" ``` "

I trigger xss. when I enter third.

Boostnote is great!

Metadata

Metadata

Assignees

No one assigned

    Labels

    bug 🐛Issue concerns a bug.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions