magic-FE / translate-man

An excellent google translation plug-in, you will love it
MIT License
276 stars 40 forks source link

Cross site scripting attack vulnerability #49

Open ymyf opened 6 years ago

ymyf commented 6 years ago

This plugin has the function of automatic translation after word segmentation. When XSS statements are entered, malicious code is executed. For example, 哈哈哈 "><img src=1 onerror=alert (document.cookie) >" 此时会把中文翻译成英文,并且执行xss语句 This will translate Chinese into English and execute XSS statement. 1 2 3

cloudfroster commented 6 years ago

Thank you for your feedback.

ymyf commented 6 years ago

You Are Welcome.