-
-
Notifications
You must be signed in to change notification settings - Fork 517
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Stored XSS Vulnerability #359
Comments
Thanks for opening this @prodigysml. We'll see what we can do about getting this into a future release. |
Looks to be an issue with how jQuery Bootgrid is re-rendering the table. Although we have escaped the data with Laravel, Bootgrid re-inserts the cell data in a Looks like there is an open PR on the Bootgrid repo for this, but there is a fix that we could make on our side: It does remove the XSS issue, but of course it's not ideal and it's not a blanket solution. @austintoddj thoughts? I'll PR it if you're happy with this as a fix. @prodigysml thanks for raising an issue; have you found any other instances? |
First off, thanks for taking the time to create the issue. Closing because everything v3.x related will remain as-is and won’t receive anymore updates. The next release is slated for this week, so stay tuned! |
Description
An attacker can arbitrarily execute JS code in another user's browser.
Steps to reproduce
<img src=x onerror=alert(1)>
Remediation
When printing this variable out, simply HTML encode it.
The text was updated successfully, but these errors were encountered: