BBCodeParser icon indicating copy to clipboard operation
BBCodeParser copied to clipboard

XSS Injection w/ [img] tag in default tags

Open BrokenR3C0RD opened this issue 9 years ago • 0 comments

Due to the URL of [img] tags not being checked, one could type: [img]test.jpg" onError="alert('hi')[/img]] Which shows existence of a possible XSS exploit. This is a critical issue in my opinion, and one that should be fixed ASAP.

BrokenR3C0RD avatar Nov 12 '16 01:11 BrokenR3C0RD