|
|
|
|
|
by arkadiyt
1306 days ago
|
|
Heads up this is vulnerable to cross site scripting [1]. If someone submits a link like: https://example.com"><script>alert(1)</script>
Then simply viewing the hackernews index page with this extension installed will let the submitter execute whatever javascript they want in your logged in hackernews context - no user interaction necessary.[1]: https://github.com/MostlyEmre/hn-anti-paywall/blob/main/scri... |
|
GreasyFork build is also updated. I recommend anyone who installed the userscript (thanks!) to update.