You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since you don't need any approval to send link to the preview page this means stored xss can be achieved without a major issue.
Even if the preview will only be available to owners this is still a major issue since if we assume most owners will not have basic programming skills and wont be able to manually review the commit going into the preview page with injected code will allow taking over the owner account
I know this project is still very young but it is probably something you'll want to address sooner than later.
The text was updated successfully, but these errors were encountered:
It seem like it is possible to inject code into commits -
https://mavo.io/demos/homepage/?lite=&homepage-storage=https%3A%2F%2Fgithub.com%2Fyonjah%2Fdata-1%2Fhomepage.json
Since you don't need any approval to send link to the preview page this means stored xss can be achieved without a major issue.
Even if the preview will only be available to owners this is still a major issue since if we assume most owners will not have basic programming skills and wont be able to manually review the commit going into the preview page with injected code will allow taking over the owner account
I know this project is still very young but it is probably something you'll want to address sooner than later.
The text was updated successfully, but these errors were encountered: