phachon / mm-wiki

MM-Wiki 一个轻量级的企业知识分享与团队协同软件,可用于快速构建企业 Wiki 和团队知识分享平台。部署方便,使用简单,帮助团队构建一个信息共享、文档管理的协作环境。

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

The markdown editor exist a XSS

Ed1s0nZ opened this issue · comments

xxxxxHere is the problem descriptionxxxx

  1. The version number in use
    vx0.2.1

  2. Whether the version has been upgraded to the new version
    yes

  3. Current problems encountered:
    The markdown editor exist a XSS

  4. Error logs or screenshots
    Insert the XSS-payload into it
    图片
    图片

  5. How to repair
    Filter user input and add http-only ...