yuki-kimoto / gitprep

Portable GitHub system into your own server
http://gitprep.yukikimoto.com/
906 stars 118 forks source link

fix stored XSS in README.md and Wiki pages #163

Open Ilya33 opened 4 years ago

Ilya33 commented 4 years ago

Hello.

I found stored XSS in README.md and Wiki pages. Examples of XSS code: "><img src=1 onerror="alert(1)"> [a](javascript:prompt(document.cookie)) <h3 onmouseover="alert(5)">XSS</h3>

This commit fix it.

Best Regards, Ilya Pavlov