-
-
Notifications
You must be signed in to change notification settings - Fork 183
Closed
Labels
enhancementImprovement requestImprovement request
Description
Hey,
someone pointed out an issue in another Angular markdown library about XSS vulnerability and it seems that this library presents the same issue as well.
Links are not being validated and as such, the following code could be used to execute javascript code:
[Click Me](javascript:alert('Injected!'%29)
Metadata
Metadata
Assignees
Labels
enhancementImprovement requestImprovement request