Skip to content

XSS vulnerability on API promotion sub-model #750

@pascalchevrel

Description

@pascalchevrel

This was reported via Bugzilla (https://bugzilla.mozilla.org/show_bug.cgi?id=1277512)
https://transvision.mozfr.org/?whole_word=on&sourcelocale=af&repo=beta&case_sensitive=on&perfect_match=on&locale=af&search_type=entities&recherche=555-555-0199@example.com&%22%3E%3Cscript%3Ealert%281%29%3C/script%3E=1

leads to a XSS because in parsing the url to extract GET keys and values, we don't sanitize the keys and we do use those when rebuilding links to point to the API.

I have a patch.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions