Skip to content

Instantly share code, notes, and snippets.

@mediaupstream
Created October 9, 2012 09:33
Show Gist options
  • Select an option

  • Save mediaupstream/3857647 to your computer and use it in GitHub Desktop.

Select an option

Save mediaupstream/3857647 to your computer and use it in GitHub Desktop.
Simple Markdown XSS
# Markdown XSS
![uh](http://example.com"onerror="javascript:alert\('hello, xss'\))
@mediaupstream

Copy link
Copy Markdown
Author

uh

@mediaupstream

Copy link
Copy Markdown
Author

Doesn't seem to effect GitHub flavoured Markdown ;)

@Download

Download commented Nov 27, 2018

Copy link
Copy Markdown

hello what?

No also this one does not. But probably they are sanitizing the html afterwards.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment