mirror of
https://git.nadeko.net/Fijxu/invidious.git
synced 2025-06-29 02:18:24 +00:00
![]() The channel/<ucid>/playlists page was vulnerable to Cross Site Scripting
(XSS), because the different URL parameters were inserted as-is in the URL
meant for instance switching.
This vulnerability could allow an attacker to inject malicious Javascript
in the page by tricking the user to click on a crafted link.
Bug introduced in commit
|
||
---|---|---|
.. | ||
invidious | ||
invidious.cr |