Square API Leaves Apps Vulnerable to XSS Attacks
zenincognito.com
Square API Leaves Apps Vulnerable to XSS Attacks
1–3 of 3 posts
Re: Square API Leaves Apps Vulnerable to XSS Attacks
#2They can't really do it because they have no idea where the data will be used. Depending on where your app puts the data different types of encoding must be done.
Re: Square API Leaves Apps Vulnerable to XSS Attacks
#3Begs the question how can they leave the apps unaudited. 6 months on the store after someone raising this issue seems just lazy or careless on square's part.