Uploaded image for project: 'onedata'
  1. onedata
  2. VFS-6851

Share description allows to embed and execute JS in anchors

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Blocker Blocker
    • 20.02.2
    • None
    • webgui
    • None
    • Sprint 179
    • 3
    • Fixed a security issue in Oneprovider share GUI
    • Include to Changelog

      Just make a description in Markdown:

      <a href="javascript:alert('hello');">cześć</a>
      

      any JS can be executed with session of current user.

      https://github.com/showdownjs/showdown/wiki/Markdown's-XSS-Vulnerability-(and-how-to-mitigate-it)

            plgjliput Jakub Liput
            plgjliput Jakub Liput
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: