redking / chosen-dojo

Dojo Port of Chosen (https://github.com/harvesthq/chosen)
http://vafada.github.com/chosen-dojo/
Other
4 stars 5 forks source link

Vulnerable to XSS Attacks #5

Open teeohhem opened 4 years ago

teeohhem commented 4 years ago

This lib is vulnerable to XSS attacks if html/javascript is entered as a search term. The lib has many instances of innerHTML replacements where textContent should be used.

Steps to reproduce: 1) Enter