xss

in test •  7 years ago  (edited)

<img src= onerror=alert('hi,guys')>

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Amazing post

我感觉这个社区还有很多xss的

最好能赶紧的找出来,修补好,要不然是太大的安全隐患了。

再结合上csrf的话,随时都有可能会盗走钱包

不过目测 steemit 貌似全局层面上过滤过了。

<img src= onerror=alert('hi,guys')>