Closed Bug 826891 Opened 12 years ago Closed 11 years ago

alert() is fired on demo page

Categories

(developer.mozilla.org Graveyard :: Demo Studio / Dev Derby, defect)

defect
Not set
critical

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 828631

People

(Reporter: stephend, Unassigned)

References

()

Details

(Whiteboard: [site:developer.allizom.org])

Attachments

(1 file)

cc:ing Mario, because this is his content.
That's caused because of the "demo" sent has a html that is showed as origin https://developer.allizom.org. So that can result in persistent xss

(In reply to Stephen Donner [:stephend] from comment #1)
> cc:ing Mario, because this is his content.
I have filed the bug 828631 with more informations and pocs. Please close this as duplicate of bug 828631. Thanks!
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → DUPLICATE
Whiteboard: [site:developer.allizom.org]
For bugs that are resolved, we remove the security flag. These haven't had their flag removed, so I'm removing it now.
Group: websites-security
Product: developer.mozilla.org → developer.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: