Skip to content

Fix potential xss attack#730

Open
jwcooper wants to merge 1 commit into
Bttstrp:masterfrom
jwcooper:xss-html
Open

Fix potential xss attack#730
jwcooper wants to merge 1 commit into
Bttstrp:masterfrom
jwcooper:xss-html

Conversation

@jwcooper

@jwcooper jwcooper commented Jul 30, 2020

Copy link
Copy Markdown

Working example:
https://jsfiddle.net/876myrk5/

$('[data-toggle="switch"]').bootstrapSwitch({onText: ">'><details open ontoggle=confirm(document.domain)>"});

If any sites allow switches based on user submitted configuration, they could be open to this issue.

@ggkitsas

Copy link
Copy Markdown

Hi, is this fix something you consider releasing soon?

@atodorov

atodorov commented Dec 1, 2020

Copy link
Copy Markdown

@LostCrew are you open to adding co-maintainers on this repository? Myself (and possibly @asankov) would be interested b/c we depend on this.

@LostCrew

LostCrew commented Jan 3, 2021

Copy link
Copy Markdown
Member

@atodorov @asankov Where can I reach you to chat privately?

@atodorov

atodorov commented Jan 3, 2021

Copy link
Copy Markdown

@LostCrew both of our email addresses are visible in our profiles.

@austinmhyatt

Copy link
Copy Markdown

Is there anyone still working on this fix?
thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants