Hacker News new | ask | show | jobs
by tferris 5130 days ago
Please explain
2 comments

https://github.com/lakkadshah/SImple-Chat-Server/issues/1

<IMG """><SCRIPT>alert("XSS")</SCRIPT>">

When you set your name you can include arbitrary HTML it seems.

It's hard to tell.. Not sure if I am just running javascript on my machine.. It's very laggy.

Edit: Looks like it is fixed now.