Closed ThomasThelen closed 1 year ago
@ThomasThelen big thanks for finding and reporting this! I've put out a fix just now.
Thanks for the fix (and project)! I looked around the source to see if I could issue a PR-but I'm unfortunately not super familiar with scala. Looking through the commit now though, it looks nice. great work ^_^
Small bug where you can set your profile name to JS, which then gets executed on a page that has a note written by you.
To Reproduce:
<script>alert("hi")</script>