rusbrain / reps2_beta1

кузы2
http://reps2.ru
GNU General Public License v3.0
11 stars 5 forks source link

HTML tags injection #187

Open ghost opened 5 years ago

ghost commented 5 years ago

At this moment almost all controllers are using an ancient concept of storing HTML tags in database with no validation whatsoever

A few ways (there is may be a lot more) to inject anything including Githubissues.

  • Githubissues is a development platform for aggregating issues.