You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, the markdown rendering page does not sanitize user input for scripts, which can lead to Cross-site Scripting (XSS) in the markdown preview page.
Hi, Wechatsync developer!
Currently, the markdown rendering page does not sanitize user input for scripts, which can lead to Cross-site Scripting (XSS) in the markdown preview page.
Payload
PoC
Impact
Users of Wecharsync who open untrusted markdown files on the platform (i.e.,
https://www.wechatsync.com/md/
) are vulnerable to XSS attacks.Note that, since the project doesn't set the security policy, I directly report the vulnerability here.
The text was updated successfully, but these errors were encountered: