Skip to content

XSS in scaladoc search #11513

@mpollmeier

Description

@mpollmeier

To trigger the XSS vulnerability, simply paste this into the search bar, e.g. on https://www.scala-lang.org/api/2.12.8/:

"\><img/src='1'onerror=alert(777111)>{{7*7}}

The fix for this is straightforward, PR coming shortly.

All credit for finding the vulnerability goes to Yeasir Arafat:
skylinearafat@gmail.com
https://www.facebook.com/skylinearafat.arafat

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions