Skip to content

server的XSS安全问题 #18

@allen-hu-666

Description

@allen-hu-666

如果有人在消息里面输入下面这些信息会很有意思:

<img src='../content/emoji/22.gif' onload='alert("你们被我的XSS攻击!哈哈哈哈")' />这是一个攻击的消息!

建议作者把信息转义一下,直接innerHTML消息出来非常不安全

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions