Skip to content

XSS on TaxonomyController #76

@S-DICKSON

Description

@S-DICKSON
  1. Create a new taxonomy
  2. Set name to <script>alert("YOu juST beEn hackED ( ͡° ͜ʖ ͡°) ")</script>
  3. Submit
  4. See alert on the index page

This issue also occurs in TaxonController@Create.

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions