execution of javascript from filename

XMLWordPrintable

    • 6.5

      Steps to replicate:

      1. Add an attachment
      2. Rename the file to "<iframe onload=alert(1)>.txt"
      3. Copy its remove link and open the link in a new browser window
      4. Result: The JavaScript code is executed, rather than showing the "proceed w/ deletion" screen.

      Everything works normally if you just click the delete button rather than copying the link into a new tab.

            Assignee:
            Issac Gerges (Inactive)
            Reporter:
            Bernd Lindner
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: