DEV Community

Discussion on: My All-Time Favorite Demonstration of a Cross-Site Scripting Attack

Collapse
 
svenluijten profile image
Sven Luijten

You're right, the heart emoji was integral to the attack. If I recall correctly, a new escaping mechanism for how emoji were handled was deployed and caused the XSS vulnerability.