I realized today that some applications out there still use #
BBCode for non-legacy reasons. I really have no idea why anybody would do that in year 2020. It’s a very questionable decision security-wise, and it has no usability benefits either. #
infosec #
security #
XSS