Closed
Bug 897639
Opened 12 years ago
Closed 12 years ago
self-xss in thunderbird :: new mail filter
Categories
(Thunderbird :: Security, defect)
Thunderbird
Security
Tracking
(Not tracked)
RESOLVED
DUPLICATE
of bug 875818
People
(Reporter: curtisk, Unassigned)
References
Details
(Keywords: reporter-external, Whiteboard: [sg:dupe 875818][reporter-external])
From: =?iso-8859-1?B?RmFiaeFuIEN1Y2hpZXR0aQ==?= <fabiancuchietti@hotmail.com>
To: "security@mozilla.org" <security@mozilla.org>
Subject: Self-xss in Thunderbird
Date: Wed, 24 Jul 2013 15:11:38 -0300
-----//-----
Hello,
I discovered another self-xss in Thunderbird, to compose a new mail the html editor does not filter properly.
Steps to reproduce:
1) Compose a mail
2) Insert
3) HTML...
4) Now insert the following payload: "><iframe src="data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4">
Flags: sec-bounty?
Comment 1•12 years ago
|
||
This like the same underlying editor issue as bug 875818
Group: core-security
Depends on: wiretap
Comment 2•12 years ago
|
||
(In reply to Daniel Veditz [:dveditz] from comment #1)
> This like the same underlying editor issue as bug 875818
Daniel,
Could you add me to CC list of "875818" ?
Comment 3•12 years ago
|
||
Any response?
Comment 4•12 years ago
|
||
This is the same test case as bug 875818 comment 0 with the first POC. The only difference is an object versus iframe.
Hence marking this as duplicate.
Status: UNCONFIRMED → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Comment 5•12 years ago
|
||
This issue is in Editor. "Self-xss" No in reply.
Comment 6•12 years ago
|
||
Sure, in this bug you're self-injecting HTML right into your own copy of the editor. We're more concerned about the reply/forward case because then the HTML fragment comes from a potential attacker, but either way it's bad filtering in the editor itself. The only difference is how the bad HTML gets in there, but it's going to be fixed by the same filter in the editor.
Flags: sec-bounty? → sec-bounty-
Updated•11 years ago
|
Whiteboard: [reporter-external] → [sg:dupe 875818][reporter-external]
Updated•11 years ago
|
Group: mail-core-security
Updated•11 years ago
|
Group: core-security
Updated•9 months ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•