uhhh cohost.org allows arbitrary html/css in posts?!?!?!?

can someone post <div style="position: fixed; top: 0; left: 0; height: 100vh; width: 100vw; background: black; color: white;">bogos binted</div>

lol

cohost 

1. create form element with a malicious POST request
2. create label for submit button
3. size label to cover the entire screen or some important ui element (the report button, for example)
4. ???
5. profit

cohost, Post contains Code 

@f0x apparently one needs an invite code to post so could you text this for me:

<img src="invalid.tld" onerror="alert(document.cookie)"/>

If it works they really messed up, which wouldn't surprise me considering none of the inputs on the sign up page have correct labels

cohost, sickness in metaphor 

@f0x you could also do fun things like search for all boost buttons on a page and auto click them, making the post propagate virally

Follow

cohost, sickness in metaphor 

@dysphoricunicorn yes, like the tweetdeck xss self-boosting tweet :D

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.