sebsauvage / MinigalNano

GNU Affero General Public License v3.0
161 stars 50 forks source link

xss #102

Closed tmos closed 8 years ago

tmos commented 9 years ago

Example : http://galerie.geekz0ne.fr/%22onmouseover%3d%27prompt%2800213771818860%29%27bad%3d%22%3E

tmos commented 9 years ago

Just added a small htmlspecialchars function. Can someone confirm that the XSS is fixed ? I'm far from being an expert on this topic, so mutual review may be a plus.