Meteor-Community-Packages / Meteor-Community-Packages/meteor-tabular

Cross-Site Scripting (XSS)

Open
#331 2 comments 0 reactions 0 assignees Claimed by @guncebektas View on GitHub
potential bug will accept pull request
Dominant language
JavaScript
Stars
360
Forks
132
PR merge metrics
No merged PRs in 30d

Description

I've been using Tabular the last few weeks and today I realized that there is an XSS vulnerability when the data is obtained from the collection for the columns.

Is there any solution?

captura de pantalla 2016-07-18 a las 12 06 26 a m

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the issue's screenshot and linked pull request #450, then reproduce the reported XSS with data obtained from a collection and displayed in a column. Done means the reported input no longer executes when rendered.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.