codex-team/moduleDispatcher

Use hidden textarea to pass settings instead of <module-settings>

Closed this issue · 0 comments

Due to XSS vulnerability. Current scheme (JSON in html-tag) does not work correctly with HTML entities and quotes.