execution of javascript from filename

XMLWordPrintable

    • 6.5

      Steps to replicate:

      1. Add an attachment
      2. Rename the file to "<iframe onload=alert(1)>.txt"
      3. Copy its remove link and open the link in a new browser window
      4. Result: The JavaScript code is executed, rather than showing the "proceed w/ deletion" screen.

      Everything works normally if you just click the delete button rather than copying the link into a new tab.

              Assignee:
              Issac Gerges (Inactive)
              Reporter:
              Bernd Lindner
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: