Uploaded image for project: 'JCommune'
  1. JCommune
  2. JC-1300

XSS: possibility to enter code in pagination

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 1.3 Larks
    • Fix Version/s: 1.4 Larks
    • Labels:
      None
    • Sprint:
      1.3 Larks, 1.4 Larks

      Description

      Steps to reproduce:
      1. Go to http://uat.jtalks.org/jcommune/search/?searchText=%3CMETA+HTTP-EQUIV%3D%27Refresh%27+content+%3D%270%3B+URL%3Dhttp%3A%2F%2Fya.ru%27%3E

      Actual Result: Code is shown in pagination
      Expected result: there is page numbers in pagination field

        Attachments

          Issue Links

            Activity

            Hide
            nkozlov Kozlov Nikita added a comment -
            1. Как воспроизвести у себя это локально?
            2. Какие топики нужно создать и какой запрос поисковый сделать?
            3. Воспроизводится ли этот баг при любом поисковом запросе?
            Show
            nkozlov Kozlov Nikita added a comment - Как воспроизвести у себя это локально? Какие топики нужно создать и какой запрос поисковый сделать? Воспроизводится ли этот баг при любом поисковом запросе?
            Hide
            julik Julia Atlygina added a comment -

            1. You can enter following search request for ex.:

            '> http

            2. Doesn't matter what topic have been created.
            3. No

            Show
            julik Julia Atlygina added a comment - 1. You can enter following search request for ex.: '> http 2. Doesn't matter what topic have been created. 3. No
            Hide
            nkozlov Kozlov Nikita added a comment -

            Первый баг фикс, пока проревьюил проект, понял более мене что к чему.
            В итоге сделал.

            Show
            nkozlov Kozlov Nikita added a comment - Первый баг фикс, пока проревьюил проект, понял более мене что к чему. В итоге сделал.
            Hide
            nkozlov Kozlov Nikita added a comment - - edited

            Done.
            Branch:origin/develop.NKozlov

            Show
            nkozlov Kozlov Nikita added a comment - - edited Done. Branch:origin/develop.NKozlov
            Hide
            ctapobep Stanislav Bashkyrtsev added a comment -

            Please, change tabs back to spaces.

            Show
            ctapobep Stanislav Bashkyrtsev added a comment - Please, change tabs back to spaces.
            Hide
            nkozlov Kozlov Nikita added a comment -

            fixed

            Show
            nkozlov Kozlov Nikita added a comment - fixed
            Hide
            julik Julia Atlygina added a comment - - edited

            Original issue has been fixed, but another one still exists:

            Test Environment
            Mozilla FF

            Precondition
            create several topics satisfy your search request (with "code" text in the topic title/post for my example)

            Test Scenario

            1. go to jcommune, enter search query with / (for ex. /code)
            2. Click on the page 2

            As a result, error 404 is shown

            please, see the url: http://uat.jtalks.org/code?page=2

            (!)Note: If you use \ in the first step, PageNotFound is shown (without 404 Jcommune error)
            Separate issue has been created for this problem

            Show
            julik Julia Atlygina added a comment - - edited Original issue has been fixed, but another one still exists: Test Environment Mozilla FF Precondition create several topics satisfy your search request (with "code" text in the topic title/post for my example) Test Scenario go to jcommune, enter search query with / (for ex. /code) Click on the page 2 As a result, error 404 is shown please, see the url: http://uat.jtalks.org/code?page=2 (!)Note: If you use \ in the first step, PageNotFound is shown (without 404 Jcommune error) Separate issue has been created for this problem

              People

              • Assignee:
                julik Julia Atlygina
                Reporter:
                galina Galina
              • Votes:
                0 Vote for this issue
                Watchers:
                Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 0h
                  0h
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 6h
                  6h

                    Structure Helper Panel