Answer the question
In order to leave comments, you need to log in
XSS on page for internal use?
I want to use <code> tag in internal use page to view user data.
How much will this tag protect against xss?
Answer the question
In order to leave comments, you need to log in
If there is no escaping or filtering besides the <code> tag, then it will not help at all. Nobody hinders to write </code>alert(1);
And if there is a normal screening of an output that and <code> is not obligatory.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question