Thanks to visit codestin.com
Credit goes to github.com

Skip to content

potential XSS vulnerability #130

@backwardspy

Description

@backwardspy

hey, super cool project!

i think the file viewer is not escaping HTML tags in certain files. i noticed this when it embedded a form into a file i was looking at in one of my own projects, so i dug a little deeper to see if it could be an issue.

repro:

  1. open repo search
  2. navigate to swisskyrepo/PayloadsAllTheThings
  3. go to "files" tab
  4. view XSS Injection/README.md

this causes a number of the alerts in that file to be executed:

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions