Cross-site Scripting
GitBook allows XSS via a local .md file.
GitBook allows XSS via a local .md file.
gitook allows the injection of javascript code that be executed on the online reader.
Stored Cross-Site-Scripting (XSS) is possible by including code outside of backticks in any ebook. This code will be executed on the online reader.