You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently the document loaded from the RSS -> JSON converter is directly evaluated as javascript in the global context.
In addition, placeholders such as {url} or {title} do not have any sanitization or escaping capabilities, so if a feed contains something like <script/> tags in its URL or title it's immediately evaluated.
So in the default configuration this can only be used if www.feedrapp.info/the custom server and the RSS feed source are absolutely trusted and loaded over a secure transport.
The text was updated successfully, but these errors were encountered:
Currently the document loaded from the RSS -> JSON converter is directly evaluated as javascript in the global context.
In addition, placeholders such as
{url}
or{title}
do not have any sanitization or escaping capabilities, so if a feed contains something like<script/>
tags in its URL or title it's immediately evaluated.So in the default configuration this can only be used if www.feedrapp.info/the custom server and the RSS feed source are absolutely trusted and loaded over a secure transport.
The text was updated successfully, but these errors were encountered: