xenocrat / chyrp-lite

An ultra-lightweight blogging engine, written in PHP.
https://chyrplite.net/
BSD 3-Clause "New" or "Revised" License
402 stars 42 forks source link

Add `scripttags` to themes when rendering data #152

Closed noobpk closed 2 years ago

noobpk commented 2 years ago

Fix bug multiple stored xss in parameter 'title' and 'body' when Write content Disclosure : https://huntr.dev/bounties/edit/7d976069-12d6-4290-9a4a-2741ab23acf6/

xenocrat commented 2 years ago

Authors have the ability to use raw HTML in posts and pages if desired. This is not an XSS, it is a feature mentioned prominently in the readme file.