Skip to content

rustdoc search xss exploit #13884

Closed
@misterhat

Description

@misterhat

The input for doc searches isn't sanitized, allowing for arbitrary HTML input.

http://static.rust-lang.org/doc/master/std/index.html?search=%3Cxmp%3E

Metadata

Metadata

Assignees

No one assigned

    Labels

    T-rustdocRelevant to the rustdoc team, which will review and decide on the PR/issue.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions