Check for xss with selenium
Set all user-changable attributes of models to something like foo<script>alert("xss");</script>
, and check if an alert shows up.
-
Milestone changed to Nice to have
Toggle commit list -
Assignee removed
Toggle commit list
Please
register
or
sign in
to comment