Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fixed missing HTML sanitization (#1)
It was possible to run arbitrary javascript from restoring a crafted teambuilder backup. Let me know if a Smogon bug report with clarification is needed. A sample: paste the following into the backup menu and restore, the effect is immediate. === [<script>alert("hi i'm from an arbitrary script!");</script>] Untitled 1 ===
- Loading branch information