Skip to content
This repository has been archived by the owner on Jul 27, 2023. It is now read-only.

The content of a textinput field is executable #40

Open
albertborsos opened this issue Jan 6, 2022 · 0 comments
Open

The content of a textinput field is executable #40

albertborsos opened this issue Jan 6, 2022 · 0 comments

Comments

@albertborsos
Copy link

This line is pretty dangerous. Try to update a value to phpinfo in a textinput editable field, and refresh the page.

} elseif (is_callable($value)) {

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant