Open tjsavage opened 10 years ago
ex.
<style is="core-style" type="polymer/style"> .span::before { content: "<script>alert(1)</script>"; } </style>
Using today to do that will alert since it just has random HTML inside it which is both slower for the parser, and will interpret stuff inside it as tags. Instead it should work as above.
ex.
Using today to do that will alert since it just has random HTML inside it which is both slower for the parser, and will interpret stuff inside it as tags. Instead it should work as above.