Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS injection vulnerability found #7

Open
Ystalard opened this issue Sep 29, 2021 · 0 comments
Open

XSS injection vulnerability found #7

Ystalard opened this issue Sep 29, 2021 · 0 comments

Comments

@Ystalard
Copy link

Ystalard commented Sep 29, 2021

  1. Create an annotation
    image
  2. Edit by inserting a script in the text field, Click on save button then cancel at connexion request
    image
  3. Click on cancel button of the annotation
    image
    4.Assert an injection is made
    image

This issue was found on v1.0. Comparing v1.0 to latest one seems not to show modification which would correct this.

Thx,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant