rich
rich
Thanks @andrew-3 , the exploit code paste wasn't 100% correct. I have not had time but I suspect this could be used in a number of different ways to inject...
> @richxrich wouldn't you expect html to be allowed to be pasted into the paragraph? This is the config, the variable fields such as label, type, class etc.... this data...
I found this not working at all, even on the demo website it is not working. I'm guessing there was a change in how browsers operate select functions? I fixed...