I'm a little bit confused regarding vue.js vulnerability to XSS attacks. My case is as follows:
- take input from user (let's say simple open text), let's say: input_text
- save it to database
- on other page load it to vue variable inputed_text
- show it with
<p>{{ inputed_text }}</p>
And now the question is: am I vulnerable to XSS attack? I tried a few solutions:
- Sanitize input on server-side - but the problem is, that vue.js shows input encoded (so I need to use v-html)
- No sanitization at all - because of auto-sanitizing from Vue.js during rendering output
In both cases I tested:
alert('XSS')
<script>alert('XSS')</script>
{{ alert('XSS') }}
{{constructor.constructor("alert('xss')")() }}
No effect at all (XSS attack not possible). So now: how it should be done correctly? Or there is a possibility to XSS, but I don't see it?