Skip to content

Conversation

@dops
Copy link
Owner

@dops dops commented Apr 23, 2018

It es possible to name html tags in the query parameter. On this way xss attacks are possible. If you, for example, have a query like this

query=">trolopwnd<img+src%3Dy+onerror%3Dprompt('openbugbounty')>

a foreign js script will be executed when the search is finished.

  • Solves issue #
  • Description

Please note that the source and target branch must be "development" (details: https://github.com/FACT-Finder/FACT-Finder-PHP-Library/wiki/Guide-for-contributors).

…xss attacks are possible. If you, for example, have a query like this

query=">trolo<i>pwnd<img+src%3Dy+onerror%3Dprompt('openbugbounty')>

a foreign js script will be executed when the search is finished.
@dops dops merged commit 257b4a5 into development Apr 23, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants