•  
      request #3165 XSS vulnerability with BookMark
    Infos
    #3165
    Mohamed Amin Doghri (doghrim)
    2013-04-25 10:46
    2013-04-18 12:33
    2006
    Details
    XSS vulnerability with BookMark
    Js code is interpreted by navigator when put in Bookmark Title.

    To reproduce :

    Login in tuleap

    Click on "BookMark this page"

    Click on "Edit this bookmark"

    In BookMark title put this string: "<script type="text/javascript">alert('test')</script>"

    Return to your personal page

    You will get an alert
    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Mohamed Amin Doghri (doghrim)
    Closed
    2013-04-25
    Attachments
    Empty
    References
    Referencing request #3165

    Follow-ups

    User avatar
    Merged in the upcoming Tuleap 6. Thanks for your contribution!

    • Status changed from Under implementation to Closed
    • Close date set to 2013-04-25
    • Platform set to
    • Is an Enhancement or an internal improvement? set to