Uploaded image for project: 'JCommune'
  1. JCommune
  2. JC-1741

Search: layout can be broken via XSS Script

VotersWatchers
    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 2.4 Larks
    • Fix Version/s: 2.6 Larks
    • Labels:
      None
    • Environment:

      Firefox 26

    • Sprint:
      2.6 Larks

      Description

      Precondition

      • open jcommune main page

      Test data

      • <xml id="X"><a><b><script>document.vulnerable=true;</script>;

      Steps to reproduce

      • Enter Test data in field Search
      • Look at result

      Actual result: layout is broken (see. actual_result_XSS)
      Expected result: just topic with "<xml id="X"><a><b><script>document.vulnerable=true;</script>;" text is shown

        Attachments

          Issue Links

            Structure

              Activity

                People

                • Assignee:
                  Vtech Targa Florio
                  Reporter:
                  vause Bogdanov Igor
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  6 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    Time Tracking

                    Estimated:
                    Original Estimate - 0h
                    0h
                    Remaining:
                    Remaining Estimate - 0h
                    0h
                    Logged:
                    Time Spent - 5h
                    5h

                      Structure Helper Panel