AevoA
Aevo
2d ago

Potential Cross-Site Scripting Payload

<img src=x onerror=alert(1)>
ClosedClosed

changed status toClosed·yesterday
yesterday

there should be no place in the app where HTML is accepted and therefore not run. Where needed it will escape syntax properly.

changed status toReviewing·yesterday