Skip to content

XSS vulnerability with bag.do #2425

@aturling

Description

@aturling

Our security team found a cross-site scripting vulnerability in bag.do with subtabs, for example:

(mine_url)/bag.do?subtab=%22%3E%3C%2Fa%3E%3CScRiPt%3Ealert%28%27w1b8m6yewq%27%29%3C%2FsCrIpT%3E%22%3E%3Cscript%3Ealert(150)%3C/script%3E

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions