enjoyreading2 icon indicating copy to clipboard operation
enjoyreading2 copied to clipboard

DOM nodes from HTML strings containing unsanitized data

Open lrem opened this issue 10 years ago • 0 comments

Leszek Życzkowski:

Your add-on creates DOM nodes from HTML strings containing unsanitized data, by assigning to innerHTML or through similar means. Aside from being inefficient, this is a major security risk. For more information, see https://developer.mozilla.org/en/XUL_School/DOM_Building_and_HTML_Insertion

lrem avatar Sep 12 '13 13:09 lrem