Freedium-cfd / web

THIS REPOSITORY IS JUST MIRROR! Main development repository is https://codeberg.org/Freedium-cfd/web
https://codeberg.org/Freedium-cfd/web
724 stars 57 forks source link

It seems under xss attack. #27

Closed shuvo5cis closed 1 month ago

shuvo5cis commented 1 month ago

While trying to enter an write-ups it’s showing a pop up like reflected xss. Also it’s not showing the full article. Check it now.

1000029390.jpg

ZhymabekRoman commented 1 month ago

Yes, it is. I'm working on a new web frontend and a new backend, although it will take a while. I can't estimate how much would be required to finish rewriting the whole project...

1ikeadragon commented 1 month ago

I was just about to open an issue for the same. I suggest adding a disclaimer on the site as threat actors can hide payload at the bottom of a sub-only article which will not be caught by the user but executed.

ZhymabekRoman commented 1 month ago

Fixed