top | item 46166318

(no title)

tripplyons | 2 months ago

Definitely! In 2020, I reported an XSS vulnerability in GitLab using the onLoad attribute to run arbitrary JavaScript, and I was able to perform user actions without requiring any user interaction. For some reason it took them months to fix it after I reported it to them.

discuss

order

No comments yet.