Conversation
Notices
-
@alex doesnt work for me
-
@zero @meso @alex The XSS is likely in the DM on that screenshot, public posts left on that instance do nothing. You can guess the chances of it getting reported to upstream.
-
@meso @alex same, maybe cause I'm on older PleromaFE tho
-
@alex <a href='data<script><script\" src="/media/bd9ba60cefe8156fccc5bd9d6ee0e06e534d4d7d513890968d39b0e4bceb911a.js">'> this doesnt work for me i mean
-
@mint @meso @alex I think I just found one that works if the FE is in an improperly configured subdomain without CSP to block inline JS eugh