lego37yoon / SBMiniDic

[Toy Project] Daum unofficial small dictionary / kakao i translator for Firefox
MIT License
2 stars 0 forks source link

Unsanitized data can make XSS attack #19

Closed lego37yoon closed 2 years ago

lego37yoon commented 2 years ago

Daum Dictionary unofficial API and Kakao i Translate sends normal data, however, because of DNS manipulation attack and any other attacks that tries XSS attack can be applied with this extension.

Firefox AddOns reviewer recommends this article to sanitize data.

It must be fixed in 1.1.3. not 1.2