Closed Bug 780049 Opened 12 years ago Closed 6 years ago

Kuma: RSS - Attempted XSS can cause funky output in RSS feed

Categories

(developer.mozilla.org :: Security, defect, P3)

defect

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: sheppy, Unassigned)

Details

(Keywords: in-triage, wsec-xss)

Attempts at XSS (such as a title of "User:x002'>"><img src=x onerror=alert(1)>") can cause completely borked output in the RSS feed of changes.
Could be HTML in general.
Priority: -- → P2
Version: Kuma → unspecified
Component: Website → Landing pages
Component: Landing pages → Design / user experience
Adding keywords to bugs for metrics, no action required.  Sorry about bugmail spam.
Keywords: wsec-xss
Component: Design / user experience → General
Is this still happening, sheppy?
Component: General → Security
Flags: needinfo?(eshepherd)
Priority: P2 → P3
Wontfix until someone comes up with a reasonable example.
Status: NEW → RESOLVED
Closed: 6 years ago
Flags: needinfo?(eshepherd)
Keywords: in-triage
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.