We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
I have the following Code:
const userInput = 'https://heise.de" onmouseover="alert(document.cookie)"'; const html = '<a href="' + xss(userInput) + '">link</a>';
the output of html is the following: '<a href="https://heise.de" onmouseover="alert(document.cookie)"">link</a>'
html
'<a href="https://heise.de" onmouseover="alert(document.cookie)"">link</a>'
This leads to an xss Attack. Is this a general problem with this library or am i using it wrong?
The text was updated successfully, but these errors were encountered:
I figured it out. Using escapeAttrValue is the correct function for this case.
escapeAttrValue
Sorry, something went wrong.
No branches or pull requests
I have the following Code:
the output of
html
is the following:'<a href="https://heise.de" onmouseover="alert(document.cookie)"">link</a>'
This leads to an xss Attack. Is this a general problem with this library or am i using it wrong?
The text was updated successfully, but these errors were encountered: