Program output is not escaped
The program output returned by the backend is not escaped by the frontend. Instead the output is wrapped in
Submitted by Vlad Vergu on 24 February 2013 at 18:41<pre></pre>
tags. This exposes the viewer of a submission to a possible HTML/JavaScript injection attack.
Issue Log
On 25 February 2013 at 09:06 Eelco Visser commented:
Fixed. Compiler output was using
rawoutput
instead of regularoutput
.
On 25 February 2013 at 09:06 Eelco Visser closed this issue.
On 25 February 2013 at 09:06 Eelco Visser tagged 0.36
Log in to post comments