Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ADMIN: Add purify.js to Stop XXS Attacks on Admin. #10346

Merged
merged 2 commits into from
Jul 14, 2020
Merged

ADMIN: Add purify.js to Stop XXS Attacks on Admin. #10346

merged 2 commits into from
Jul 14, 2020

Conversation

MatthewKennedy
Copy link
Contributor

It is possible to execute scripts by entering them into the search filter bar, for example: '<p>abc<iframe//src=jAva&Tab;script:alert(3)>def</p>' in the filter search bar runs the alert just fine.

Screenshot 2020-07-12 at 22 35 09

Added purify.js and clean the label tag.

@squash-labs
Copy link

squash-labs bot commented Jul 12, 2020

Manage this branch in Squash

Test this branch here: https://matthewkennedyadmin-xxs-wurvd.squash.io

@damianlegawiec damianlegawiec merged commit 457bedd into spree:master Jul 14, 2020
@damianlegawiec damianlegawiec added security Pull requests that address a security vulnerability Admin Panel ⚙️ labels Jul 14, 2020
@MatthewKennedy MatthewKennedy deleted the admin-xxs branch July 14, 2020 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Admin Panel ⚙️ security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants