bustle / mobiledoc-dom-renderer

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

XSS Fix bypass

niksthehacker opened this issue · comments

Hi,

The XSS fix for href can easily be bypassed using

jaVasCript: 

Pattern. Please have a look.

Regards,
Nikhil

Closed by #60