Closed Bug 1067996 Opened 11 years ago Closed 11 years ago

Reflected XSS in mxr.mozilla.org

Categories

(Webtools Graveyard :: MXR, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 949514

People

(Reporter: danhmcinerney, Unassigned)

Details

(Keywords: reporter-external, sec-high, wsec-xss)

Attachments

(1 file)

Attached image mozillaXSS.png
User Agent: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.120 Safari/537.36 Steps to reproduce: 1. With Firefox, go to http://mxr.mozilla.org/mozilla-central/source/nsprpub/pr/include/prtime.h/%3Csvg%20onload=prompt%284%29%3E 2. Notice JS pop up. Just tack on a '/' + XSS payload to the end of the URL for many of these http://mxr.mozilla.org/mozilla-central/source/browser/devtools/... domains and you'll get XSS'ed. Some more examples: http://mxr.mozilla.org/mozilla-central/source/browser/devtools/tilt/TiltWorkerPicker.js/%3Csvg%20onload=prompt%284%29%3E http://mxr.mozilla.org/mozilla-central/source/mobile/android/base/toolbar/%3Csvg%20onload=prompt%284%29%3E Actual results: A javascript pop up appeared after entering the payloaded URL. Expected results: The input should've been filtered.
Component: Security Assurance: Applications → Security Assurance
I could reproduce the XSS.
Group: mozilla-employee-confidential → webtools-security
Status: UNCONFIRMED → NEW
Component: Security Assurance → MXR
Ever confirmed: true
Keywords: sec-high, wsec-xss
Product: mozilla.org → Webtools
CCing fubar: Should this be assigned to you?
Flags: sec-bounty?
Didn't we recently (try to) fix a similar XSS issue? :-\ No, code changes don't go to me, I just manage the deploys. I think :dkl got the last code change, but check with :mcote for his availability or alternative.
Aha, Bug 949514. Same thing?
My bad. I was surprised I didn't find a duplicate. Maybe I should have looked harder. Thanks fubar!
Status: NEW → RESOLVED
Closed: 11 years ago
Flags: sec-bounty? → sec-bounty-
Resolution: --- → DUPLICATE
Sorry for the confusion, Dan! You have been copied into the existing bug <https://bugzilla.mozilla.org/show_bug.cgi?id=949514>, which was already discussed and resolved earlier.
Group: webtools-security
Product: Webtools → Webtools Graveyard
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: