-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Open
Description
XSS Vulerability detected:
I tried using Inject an XSS query in simple MDE, By creating a link as following.
[XSS](javascript:alert%28sessionStorage.clear%28%29%29)
and it works as following:
This converted into a link, that clears users sessionStorage in this example while clicking
skix123, pranavstark, matiishyn, MadanBhandari, njourdane and 2 more
Metadata
Metadata
Assignees
Labels
No labels