Birdwatch Note Rating
2023-12-11 17:59:41 UTC - HELPFUL
Rated by Participant: ADFA74B9DAE8B0B9F165B6DA276DAB3E76DC553656E4D5DA1C2E31D8C92E73C0
Participant Details
Original Note:
According to OWASP, HTML Injection can allow arbitrary JavaScript code execution via event handlers. However, this rests on the assumption that CS2 both embeds a JS interpreter and that it has access to dangerous functions and/or private user data. More research is required. https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/11-Client-side_Testing/03-Testing_for_HTML_Injection
All Note Details