saferwall/saferwall

XSS in the Comment Page

huvuqu opened this issue · 3 comments

huvuqu commented

Store XSS in the Comment Page.
You should do HTML encode all user input when return this data in HTTP response.

xss1
xss2

Hello @huvuqu

Thanks a lot for reporting, @yassinrais can you please have a look.

✅ Fixed

Deployed the new version.