Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Highcharts XSS攻击简析与修复 · Just Blog #2

Open
sjfkai opened this issue Jan 29, 2019 · 0 comments
Open

Highcharts XSS攻击简析与修复 · Just Blog #2

sjfkai opened this issue Jan 29, 2019 · 0 comments

Comments

@sjfkai
Copy link
Owner

sjfkai commented Jan 29, 2019

https://blog.sjfkai.com/2018/10/18/Highcharts-XSS%E6%BC%8F%E6%B4%9E%E7%AE%80%E6%9E%90%E4%B8%8E%E4%BF%AE%E5%A4%8D/

最近工作上接手的一个项目使用到了Highcharts。
它是一个开源图标库。
XSS攻击简析该库允许使用者传入 HTML 来自定义图表的某些部分。
比如官方实例:An HTML table in the tooltip
恰好我司业务需求中,要把用户输入的内容展示在 tooltip 中。
这就很容易出

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant