Closed
Bug 890397
Opened 13 years ago
Closed 13 years ago
Persistent Self-XSS in PopCorn WebMaker Widgets
Categories
(Webmaker Graveyard :: Popcorn Maker, defect)
Webmaker Graveyard
Popcorn Maker
Tracking
(Not tracked)
RESOLVED
DUPLICATE
of bug 866026
People
(Reporter: nishant.dp, Unassigned)
References
()
Details
(Keywords: reporter-external)
Attachments
(1 file)
|
3.05 MB,
application/octet-stream
|
Details |
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.116 Safari/537.36
Steps to reproduce:
1. Create a new project at https://popcorn.webmaker.org/
2. Choose any or all of the Events: Text, Popup, GoogleMap, WikiPedia
3. Inject the payload/vector as shown in the screenshot to trigger the XSS.
Actual results:
Persistent Self XSS vulnerability was triggered.
Expected results:
Proper escaping should have been in place to treat user string as data rather than code.
| Reporter | ||
Updated•13 years ago
|
Updated•13 years ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 13 years ago
Resolution: --- → DUPLICATE
Updated•13 years ago
|
Flags: sec-bounty-
Updated•12 years ago
|
Group: websites-security
Updated•2 years ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•