cross-posted from: https://sh.itjust.works/post/923025

lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.

It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.

  • minnieo@kbin.social
    link
    fedilink
    arrow-up
    5
    ·
    1 year ago

    it’s honestly pathetic. he hates it here so much that he spends 95% of his free time here making comments about how much better reddit is hahaha. he seems addicted to this place and addicted to the taste of shiny black boots

    • XiELEd@kbin.social
      link
      fedilink
      arrow-up
      4
      ·
      1 year ago

      I mean I get that he’s in some sort of one-way findom relationship with spez but that should be done without harassing other people— we didn’t consent to it.