Skip to content

Security Issue: XSS vulnerability in modal_helper:close_button #906

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

193s
Copy link

@193s 193s commented May 18, 2016

Proof of Concept:

= modal_header title: 'confirm', show_close: true, dismiss: 'modal"><script>alert(1)</script>'

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant