mirror of
https://github.com/minimaxir/big-list-of-naughty-strings.git
synced 2025-09-24 21:01:32 +02:00
Added Full width unicode lt/gt
Browsers will ignore the <script>, but if it's stored into a SQL varchar it get's converted into < and thus a persisted XSS
This commit is contained in:
Reference in New Issue
Block a user