Closed DanielHeath closed 4 years ago
Just tested this against the latest loofah version and got an alert(1).
alert(1)
https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/
Argh! My mistake - loofah does in fact handle this (good job!)
Just tested this against the latest loofah version and got an
alert(1)
.https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/