Skip to content
This repository has been archived by the owner on Jun 18, 2020. It is now read-only.

Rating comments can be arbitrary code #318

Closed
kcrisman opened this issue Dec 19, 2014 · 2 comments
Closed

Rating comments can be arbitrary code #318

kcrisman opened this issue Dec 19, 2014 · 2 comments
Labels

Comments

@kcrisman
Copy link
Member

E.g., try putting <script>alert('hi there')</script> in the comment box while rating a public worksheet. 'Nuff said. This was reported at http://trac.sagemath.org/ticket/8839.

@kcrisman
Copy link
Member Author

Presumably there is some standard way to sanitize this, even perhaps used elsewhere in the notebook.

@kcrisman
Copy link
Member Author

Solved by #323.

kcrisman added a commit that referenced this issue Dec 2, 2015
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant