recursecenter / community

community.recurse.com
GNU Affero General Public License v3.0
115 stars 27 forks source link

Community allows script injection? #359

Open icco opened 5 years ago

icco commented 5 years ago

See the second post in https://community.recurse.com/t/post-cats/3643/2

It has javascript inserted by a user, which could lead to leaking of user data or compromising the RC site.

davidbalbert commented 5 years ago

Thanks for reporting. I will look into this soon.

On Wed, Feb 6, 2019 at 9:25 PM Nat Welch notifications@github.com wrote:

See the second post in https://community.recurse.com/t/post-cats/3643/2

It has javascript inserted by a user, which could lead to leaking of user data or compromising the RC site.

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/recursecenter/community/issues/359, or mute the thread https://github.com/notifications/unsubscribe-auth/AAHh1irZdX9YTr9wX2HQq8_yYB4f6NSCks5vK46AgaJpZM4amfaB .