editor.md XSS via Markdown

ymzxtsji  于 2022-10-27  发布在  其他
关注(0)|答案(2)|浏览(183)

Hello, i found bug XSS via markdown
Iam using simple payload to test ><iframe src="javascript:alert(document.cookie)"</iframe>

Result:

ktecyv1j

ktecyv1j2#

Can you try against this version please, also be sure the have the iframe filter enabled:
https://github.com/418sec/editor.md

相关问题