Skip to content

Cross-Site Scripting (XSS) - DOM Based #156

Description

@Arkango

The function addTextItem doesn't properly validate the value, allowing an attacker to perform a Cross-Site Scripting (XSS) - DOM based.

The vulnerable code is the following

code_link

424 var li = $('<li rel="'+value+'" fckb="1">').html(xssDisplay(value));

The value inserted as rel value is not properly sanitized.

If the function is called with the following payload

#"><img onerorr=alert(document.domain) src=x>

The Cross-Site Scripting - DOM based will be performed.

I requested a CVE to report the vulnerability.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions