Hacker News new | ask | show | jobs
by cheb 1903 days ago
Cool site :D but consider fixing some xss issues :(. https://anon.sharehub.live/post/ckmxuf329008415mjcdmuwufu/as...
1 comments

asdfasdfasdfasdf

Didn't know you could execute javascript emebedded in an image like that. I used some basic filtering rules, but I can clearly see I have some way to go. I won't sleep tonight until I get this fixed!

EDIT: The glitch in the matrix is no more. Thank you for pointing this out!

can you share what the bug was? :)
<img onerror="<javascript injection>" />

It was redirecting users to 'never gonna give you up' on youtube. It was a noob mistake.