Meteor-Community-Packages / Meteor-Community-Packages/meteor-tabular
Cross-Site Scripting (XSS)
Open
potential bug
will accept pull request
- Dominant language
- JavaScript
- Stars
- 360
- Forks
- 132
- PR merge metrics
- No merged PRs in 30d
Description
I've been using Tabular the last few weeks and today I realized that there is an XSS vulnerability when the data is obtained from the collection for the columns.
Is there any solution?
Contributor guide
Research direction
Start by reviewing the issue's screenshot and linked pull request #450, then reproduce the reported XSS with data obtained from a collection and displayed in a column. Done means the reported input no longer executes when rendered.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100