top | item 43293787

(no title)

karol | 11 months ago

That looks like more XSS vectors.

Also what do I do if I want to fire analytics even and open the modal. Correct, use onClick.

discuss

order

kflgkans|11 months ago

> That looks like more XSS vectors.

Could you elaborate on that? I don't understand how this leads to more XSS vectors.

karol|11 months ago

If these are proposals to use bindings between html attributes and calling JS methods, then it's enough to inject HTML, not JS, to start executing JS.