-
Notifications
You must be signed in to change notification settings - Fork 24
XSS #95
Copy link
Copy link
Open
Labels
bugSomething isn't workingSomething isn't workinghelp wantedExtra attention is neededExtra attention is needed
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workinghelp wantedExtra attention is neededExtra attention is needed
Describe the bug
XSS в поле "фильтр" на главной странице
How to reproduce
https://rubyjobs.dev/?query=%22%3E%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E
Expected behavior
В инпуте юзера стрипается весь html шлак
Actual behavior
Инпут ломает форму и срабатывает как часть встроенного в страницу кода (XSS)
Additional context
Ну фундаментальная вещь же...