Closed grkb-chaziz closed 2 years ago
lol
yooo, this is epic. time to self host DVWA and practice my XSS skills :him:
ok so I fixed the XSS for comments but display names XSS seems to be hit or miss.
this will be closed when i will blacklist any unusual symbols for display names
apparently comments XSS was due to how the twig template file was made. so it didn’t filter anything whatsoever. don’t know why was it added, and when was it added.
OH MY FUCKING GOD
Comments on watch.php (fixed)
Display names on user.php