ziggi/zimg-host

xss

juggl3r opened this issue · 0 comments

file_item_error.php?name=<script>alert("hi")</script>">

just remove the \ and its an xss
you need to fix this in this file and file_item.php