mathiasbynens / jsperf.com

jsPerf.com source code
http://jsperf.com/
Other
473 stars 56 forks source link

XSS vulnerability #180

Closed wariotx closed 9 years ago

wariotx commented 10 years ago

This submitted test, when loaded redirects the user to another website http://jsperf.com/brazil-vs-colombia-fifa-world-cup-2014-free-live-stream/9

jdalton commented 10 years ago

JSPerf doesn't restrict the html you can put in a test. This is great for devs but has unfortunately this has left the door open to spammers. We've taken steps to address this in #179.