Closed Bug 771640 Opened 12 years ago Closed 12 years ago

XSS vuln on new article in Kuma editor

Categories

(developer.mozilla.org Graveyard :: Wiki pages, defect, P1)

defect

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: stephend, Unassigned)

References

()

Details

(Keywords: wsec-xss, Whiteboard: [infrasec-qa:xss] s=2012-07-25)

Attachments

(3 files)

Attached image Problematic markup
STR:

1. Load https://developer-new.mozilla.org/en-US/docs/new?slug=jkls
2. In the Title field, enter "</script><script>alert("Hi!");</script>" without the quotes
3. Do the same for the Slug and Tags fields
4. Click Preview Changes

Actual Results:

I get an alert() that says "Hi!", indicating the JS was executed

Expected Results:

No XSS :-(
Does this resolve bug 665735? To think some believe users need jsFiddle to experiment with JavaScript...
Blocks: 771763
Priority: -- → P1
(In reply to John Karahalis [:openjck] from comment #2)
> Does this resolve bug 665735? To think some believe users need jsFiddle to
> experiment with JavaScript...

I don't think this has anything to do with bug 665735
(In reply to Les Orchard [:lorchard] from comment #3)
> (In reply to John Karahalis [:openjck] from comment #2)
> > Does this resolve bug 665735? To think some believe users need jsFiddle to
> > experiment with JavaScript...
> 
> I don't think this has anything to do with bug 665735

Just a joke. :-)
Whiteboard: [infrasec-qa:xss] → [infrasec-qa:xss] s=2012-07-17
https://developer-new.mozilla.org/en-US/docs/new
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
Verified FIXED; thanks!
Status: RESOLVED → VERIFIED
Whiteboard: [infrasec-qa:xss] s=2012-07-17 → [infrasec-qa:xss] s=2012-07-25
Version: Kuma → unspecified
Component: Website → Landing pages
Adding keywords to bugs for metrics, no action required.  Sorry about bugmail spam.
Keywords: wsec-xss
For bugs that are resolved, we remove the security flag. These haven't had their flag removed, so I'm removing it now.
Group: websites-security
Product: developer.mozilla.org → developer.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: