Javi Martín
8b73cfc019
Sanitize annotation context before displaying it
...
There's a case where we would face a Cross-Site Scripting attack. An
attacker could use the browser's developer tools to add (on their
browser) a `<code>` tag with a `<script>` tag inside in the text of the
draft version. After doing so, commenting on that text would result in
the attacker's JavaScript being executed.
2019-10-08 18:46:20 +02:00
..
2019-10-07 01:56:23 +02:00
2019-10-08 13:20:22 +02:00
2019-10-08 18:46:20 +02:00
2019-10-06 19:32:04 +02:00
2019-09-10 21:04:56 +02:00
2019-10-08 18:46:20 +02:00
2019-10-08 13:20:22 +02:00
2019-10-06 19:32:04 +02:00
2019-10-07 01:56:23 +02:00
2017-09-26 13:55:28 +02:00
2019-09-10 20:02:15 +02:00
2019-03-25 14:58:54 +01:00
2019-09-10 20:02:15 +02:00
2019-10-08 13:20:22 +02:00
2019-10-08 18:46:20 +02:00
2019-10-08 18:46:20 +02:00
2019-09-10 19:21:03 +02:00
2019-10-08 18:46:20 +02:00
2019-10-07 01:56:24 +02:00
2019-10-06 19:32:04 +02:00
2019-01-24 17:40:09 +01:00
2019-10-05 04:02:39 +02:00
2019-09-10 20:02:15 +02:00
2019-10-06 19:32:04 +02:00
2019-10-08 13:20:22 +02:00
2019-10-08 13:20:22 +02:00
2019-10-05 14:07:24 +02:00
2019-10-07 01:56:23 +02:00
2019-10-08 13:20:22 +02:00
2019-09-10 21:04:56 +02:00
2019-10-07 01:56:23 +02:00
2019-09-10 20:02:15 +02:00
2019-10-07 01:56:23 +02:00
2019-10-07 01:56:23 +02:00
2019-10-08 13:20:22 +02:00
2019-10-07 01:56:23 +02:00
2019-10-08 13:20:22 +02:00
2019-09-10 20:02:15 +02:00