Closed glen-84 closed 1 year ago
Fixed
@mganss
Where can I find the source code for the demo?
For some reason my code is stripping out the style
attribute in this input:
<img src="test.png" style="background-image: url(javascript:alert('xss')); margin: 10px">
But it doesn't happen with the demo, so I want to compare the configurations.
Ah, never mind, I just noticed this in a doc comment:
Sanitizes the specified parsed HTML body fragment. If the document has not been parsed with CSS support then all styles will be removed.
The demo is using version
6.0.409.0
, whereas the latest version is8.0.645
.