-
Notifications
You must be signed in to change notification settings - Fork 986
A stored XSS #420
Copy link
Copy link
Open
LavaLite/framework
#116Description
Steps to reproduce:
1.Log in to https://lavalite.org/
2.Create a package and input <script>alert("hello")</script> into Name or Description

3.When someone searchs for “package”,the vulnerability is triggered
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels

