Uploaded image for project: 'JCommune'
  1. JCommune
  2. JC-614

Active xss can be created using code tag

VotersWatchers
    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 0.13
    • Fix Version/s: 0.13
    • Labels:
      None

      Description

      Create new post with this text:

      [code=js]<script>alert('Hi!');</script>[/code]
      Refresh page.

      AR: You'll get alert with text "Hi!"

      ER: Code succesfully highlighted

        Attachments

          Issue Links

            Structure

              Activity

                People

                • Assignee:
                  shaddy Nikita Nazarov
                  Reporter:
                  shaddy Nikita Nazarov
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  0 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    Time Tracking

                    Estimated:
                    Original Estimate - 8h
                    8h
                    Remaining:
                    Remaining Estimate - 0h
                    0h
                    Logged:
                    Time Spent - 8h
                    8h

                      Structure Helper Panel