Skip to content

< and > are not escaped in the joke submission form #68

@Sv443

Description

@Sv443

The characters < and > are not escaped when entering them in the joke submission form, therefore they can be used to "XSS yourself" or just to break the submission payload rendering.

image

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions