Text/code injection @ https://www.arcblock.io
## Summary:
I've found a TEXT/CODE injection Bug on your site https://www.arcblock.io . /.well-known/service/blocklet/og.png?title= parameter is vulnerable to TEXT/CODE injection.
## Steps To Reproduce:
- Go to https://www.arcblock.io/.well-known/service/blocklet/og.png?title=You%20have%20been%20hacked%20&description=Please%20go%20to%20https://google.com
- Get The text injection result.

## Impact
Attacker could execute text at page. As a result an attacker can fool the victim.
Thanks and Best Regards
1 reply
Hi, this issue is verified and improved in the latest beta release, however this API supports customized title and description.