<img src="x" onerror="alert('hi! here is some fresh new xss, enjoy🍴 ')">

comments (single view)

even if this worked jeffalo’s dompurify would cut the invalid src and possibly the onerror @jeffalo pls confirm

View all comments