[Plugin: Live Comment Preview] Xss in 2.0.1
-
Hi Brad.
HTML tags are not stripped from the preview in field “Name” and “Web site”. I think that HTML tags should not be allowed.Xss example:
<iframe src="https://ha.ckers.org/scriptlet.html">
Thank you.https://www.ads-software.com/extend/plugins/live-comment-preview/
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘[Plugin: Live Comment Preview] Xss in 2.0.1’ is closed to new replies.