XSS issue on HTML input using an unsanitised HTML tag
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 163
- Forks
- 104
- PR merge metrics
- No merged PRs in 30d
Description
This issue has been validated on a live customer website (I am a Penetration Tester), and on a Proof-of-Concept React app.
Due to the potential for exploitation on live websites the payload is not detailed here.
I have reached out directly to @jpuri with the payload and will update the details here when instructed to, or after a reasonable period if responses are not forthcoming.
Feel free to reach out, my goal is to enhance the security of this very useful package.
Thanks!
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names an HTML input and a proof-of-concept React app but provides no payload, source file, or test. Obtain the reproduction details from @jpuri or the reporter first, then trace the HTML input handling and verify that the reported XSS can no longer execute.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- react
- Domain
- frontend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100