Skip to content
This repository was archived by the owner on Jun 2, 2021. It is now read-only.

onclick not blocked? #34

Closed
dave-gohyperion opened this issue Apr 23, 2019 · 0 comments
Closed

onclick not blocked? #34

dave-gohyperion opened this issue Apr 23, 2019 · 0 comments

Comments

@dave-gohyperion
Copy link

dave-gohyperion commented Apr 23, 2019

Shouldn't this be blocking the following querystring:

?test=onclick="alert(document.cookie)"

Using this ruleset it allows that through the WAF. It only blocks if you add in <script> tags.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant