Skip to content

CVE-2020-8981: XSS in Delete Repository page #338

@dregad

Description

@dregad

This is related to #286.

Steps to reproduce:

  1. Create a new repository, set repo name to <script>alert('XSS');</script>
  2. Update and go back to Manage Repository page
  3. Click on Delete Repository

CVE request 841560 pending.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions