Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-6631

Setting label on the favourite item leads to its evaluation (XSS)

    XMLWordPrintable

Details

    Description

      Profile settings / Favourites.
      Apparently it is possible to click on the start and set a label on the favourite.
      Setting "my secret name for favourite <script>alert('d');</script>" label executes the alert. Visiting favourites page later (or even opening Update favourite dialog) doesn't show alert anymore.
      Seems like non-persisted XSS then, also I can't see any page to share favourites with other users, so the only potential victim of this XSS is the same user.

      Attachments

        Activity

          People

            Unassigned Unassigned
            sgladkov Stan Gladkov (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: