h9k / magirc

PHP Frontend for Anope / Denora IRC Statistics
https://h9k.github.io/magirc/
34 stars 14 forks source link

Stored XSS #113

Closed alvarodh5 closed 9 years ago

alvarodh5 commented 9 years ago

If you create a channel with your payload, you can see the injection in the 10 top channels:

Version: 1.0.0 Image: https://cloud.githubusercontent.com/assets/9592881/5864345/9f7bc3d0-a281-11e4-9994-c1cecd9870bf.png

By @alvarodh5 (twitter)

h9k commented 9 years ago

Thanks for reporting and sorry for the slow response. I believe the problem to be fixed now, I also fixed several similar issues and potential issues I could find.