jbt / markdown-editor

Live (Github-flavored) Markdown Editor
http://jbt.github.com/markdown-editor
ISC License
2.82k stars 643 forks source link

XSS vulnerability found #121

Open francoborrelli opened 4 years ago

francoborrelli commented 4 years ago

I found that you can exploit this vulnerability simply by adding an iframe <iframe src="javascript:alert(document.domain)"</iframe>