-
Notifications
You must be signed in to change notification settings - Fork 107
Open
Description
Describe the bug
When using the discord integration, using [prefix]rv will display the 10 most recent visited pages. if you send a crafted payload, you can do things like ping everyone.
To Reproduce
Steps to reproduce the behavior:
- curl https://[DOMAIN]/```@everyone - ``` breaks out of the code block, @everyone is just a PoC ping
- run [prefix]rv
- See injectionon
Expected behavior
Strip or Escaped characters so that this can't happen
ShareS Version
4.5.3
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels