Server-Side Template Injection in user input rendering <h1>z</h1>

Currently, user-provided input is being rendered directly inside a server-side template powered by Jinja2. This allows template expressions to be evaluated instead of treated as plain text.

Please authenticate to join the conversation.

Upvoters
Status

New Submission

Board
πŸ›

Bugs

Date

3 days ago

Author

Gobesh Basumatary

Subscribe to post

Get notified by email when there are changes.