February 13th, 2020 at 5:27 PM
Nice input sanitation.
Was trying to figure out why using HTML encoded payloads wasn't working in event handlers or as src="javascript:" wasn't working, then rage-clicking "Edit as HTML" led me to find &zwnj being injected in both javascript and event handlers. LOL
Dunno if you added that or if it's a MyBB feature by default, but pretty good antiXSS lmao
Was trying to figure out why using HTML encoded payloads wasn't working in event handlers or as src="javascript:" wasn't working, then rage-clicking "Edit as HTML" led me to find &zwnj being injected in both javascript and event handlers. LOL
Dunno if you added that or if it's a MyBB feature by default, but pretty good antiXSS lmao