Closed Bug 897639 Opened 12 years ago Closed 12 years ago

self-xss in thunderbird :: new mail filter

Categories

(Thunderbird :: Security, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 875818

People

(Reporter: curtisk, Unassigned)

References

Details

(Keywords: reporter-external, Whiteboard: [sg:dupe 875818][reporter-external])

From: =?iso-8859-1?B?RmFiaeFuIEN1Y2hpZXR0aQ==?= <fabiancuchietti@hotmail.com> To: "security@mozilla.org" <security@mozilla.org> Subject: Self-xss in Thunderbird Date: Wed, 24 Jul 2013 15:11:38 -0300 -----//----- Hello, I discovered another self-xss in Thunderbird, to compose a new mail the html editor does not filter properly. Steps to reproduce: 1) Compose a mail 2) Insert 3) HTML... 4) Now insert the following payload: "><iframe src="data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4">
Flags: sec-bounty?
This like the same underlying editor issue as bug 875818
Group: core-security
Depends on: wiretap
(In reply to Daniel Veditz [:dveditz] from comment #1) > This like the same underlying editor issue as bug 875818 Daniel, Could you add me to CC list of "875818" ?
Any response?
This is the same test case as bug 875818 comment 0 with the first POC. The only difference is an object versus iframe. Hence marking this as duplicate.
Status: UNCONFIRMED → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
This issue is in Editor. "Self-xss" No in reply.
Sure, in this bug you're self-injecting HTML right into your own copy of the editor. We're more concerned about the reply/forward case because then the HTML fragment comes from a potential attacker, but either way it's bad filtering in the editor itself. The only difference is how the bad HTML gets in there, but it's going to be fixed by the same filter in the editor.
Flags: sec-bounty? → sec-bounty-
Whiteboard: [reporter-external] → [sg:dupe 875818][reporter-external]
Group: mail-core-security
Group: core-security
You need to log in before you can comment on or make changes to this bug.