You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This issue happens for all cities that use your product.
Within the /search view, you can use the filter parameters to run Javascript code in an HTML script tag. See the following for an example:
Thanks very much for reporting this vulnerability. We've got a fix open in #271 and will update this issue as soon as we've patched production systems.
We released 2.5.9 to fix this bug. The fix is currently being rolled out to LA Metro, and we're working on logistics to do it for Chicago and New York as well.
This issue happens for all cities that use your product.
Within the
/search
view, you can use the filter parameters to run Javascript code in an HTML script tag. See the following for an example:I attempted to do the same on http://philly.councilmatic.org/, but it ended up breaking and showing a Heroku error.
The text was updated successfully, but these errors were encountered: