Closed gordonwoodhull closed 4 years ago
It's possible to create a name for a group such that, when invoking notebook info for a notebook belonging to that group, will run bits of the group name as JS in the client.
Notebook name in this popup was also vulnerable
It's possible to create a name for a group such that, when invoking notebook info for a notebook belonging to that group, will run bits of the group name as JS in the client.