Uploaded image for project: 'Antarcticle'
  1. Antarcticle
  2. ANTARCTICLE-192

XSS vulnerability in comments

VotersWatchers
    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 2.0
    • Fix Version/s: 2.0
    • Labels:

      Description

      Steps to reproduce:
      1. Log into antarcticle
      2. Open an article
      3. Enter <script>alert("test")</script> comment, click "Post"

      Actual result: alert window pops-up
      Expected result: no pop-up window is shown, script is saved as a text

        Attachments

          Issue Links

            Structure

              Activity

                People

                • Assignee:
                  Vtech Targa Florio
                  Reporter:
                  Vtech Targa Florio
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  3 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    Structure Helper Panel