Closed Bug 890397 Opened 13 years ago Closed 13 years ago

Persistent Self-XSS in PopCorn WebMaker Widgets

Categories

(Webmaker Graveyard :: Popcorn Maker, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 866026

People

(Reporter: nishant.dp, Unassigned)

References

()

Details

(Keywords: reporter-external)

Attachments

(1 file)

3.05 MB, application/octet-stream
Details
Attached file popcorn-xss.zip
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.116 Safari/537.36 Steps to reproduce: 1. Create a new project at https://popcorn.webmaker.org/ 2. Choose any or all of the Events: Text, Popup, GoogleMap, WikiPedia 3. Inject the payload/vector as shown in the screenshot to trigger the XSS. Actual results: Persistent Self XSS vulnerability was triggered. Expected results: Proper escaping should have been in place to treat user string as data rather than code.
Status: UNCONFIRMED → RESOLVED
Closed: 13 years ago
Resolution: --- → DUPLICATE
Group: websites-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: