EdOverflow

Results 13 issues of EdOverflow

Hi KingPixil, Lock is vulnerable to stored XSS, a form of code injection wherein one can execute malicious scripts into a page. # Why does this vulnerability exist? Cross-site scripting...

This is a ticket to report a security issue in gitment. In your README.md under "_Is it safe to make my client secret public?_" you state the following: > Client...

The following input field where output is displayed results in Firefox users not being able to copy the address: https://github.com/taviso/rbndr/blob/master/rebinder.html#L50. The field is completely disabled on Firefox. ```html ``` Of...

Someone requested this via email: > Please add a security.txt checker/validator on the securitytxt.org site. People seem to have a hard time understanding the specification fully, so a checker would...

enhancement

The current label is a bit confusing. Maybe we could reword it. ![image](https://user-images.githubusercontent.com/18099289/83649174-33825880-a5b7-11ea-8ead-2ef3bbaa2fd3.png) ![image](https://user-images.githubusercontent.com/18099289/83649306-544aae00-a5b7-11ea-83a8-d284e07903f1.png)

Currently we only have a twitter share widget. We should add other options. ![](https://user-images.githubusercontent.com/18099289/82217937-6ff95780-991b-11ea-82e8-da1979b242db.jpeg)

enhancement

Someone brought it to my attention that the form does not work for Tor users because of Cloudflare's WAF rules. We load the JavaScript files from Cloudflare's CDN which is...

bug

Added: - University of Waterloo - University of Education Zurich - Karlsruhe Institute of Technology - Embry–Riddle Aeronautical University - Lyon College These are some of the unis that I...

Would it make sense to include a requirement concerning `security.txt` labelling in images? Some organisations already do this such as [Atlassian](https://hub.docker.com/layers/atlassian/jira-software/8.21.0-EAP01/images/sha256-86051be29383e24f7fe28951780765f4667943ae8314b5e1cfea64ccad1da0ba?context=explore). ``` LABEL securitytxt=https://www.atlassian.com/.well-known/security.txt ``` This might fit into the...

![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123) ### Snyk has created this PR to fix 1 vulnerabilities in the rubygems dependencies of this project. #### Snyk changed the following file(s): - `Gemfile` - `Gemfile.lock` #### Vulnerabilities...