.html does not escape any html input in these, leading to XSS attack vectors. Thanks to A Kai (@sixhundredns) for reporting the related issues. |
||
|---|---|---|
| .. | ||
| images | ||
| javascripts | ||
| stylesheets | ||
| templates | ||
.html does not escape any html input in these, leading to XSS attack vectors. Thanks to A Kai (@sixhundredns) for reporting the related issues. |
||
|---|---|---|
| .. | ||
| images | ||
| javascripts | ||
| stylesheets | ||
| templates | ||