AUR web interface

Tasklist

FS#45284 - XSS in Manage Co-maintainers Input

Attached to Project: AUR web interface
Opened by Emanuel Duss (mindfuckup) - Tuesday, 09 June 2015, 21:26 GMT
Last edited by Lukas Fleischer (lfleischer) - Wednesday, 10 June 2015, 06:57 GMT
Task Type Bug Report
Category Backend
Status Closed
Assigned To No-one
Architecture All
Severity Low
Priority Normal
Reported Version 4.0.0-rc2
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

It's possible to insert HTML and JavaScript code in the textbox where I can add Co-maintainers.

I think it's not critical, because the token must be sent on every request.
This task depends upon

Closed by  Lukas Fleischer (lfleischer)
Wednesday, 10 June 2015, 06:57 GMT
Reason for closing:  Fixed
Additional comments about closing:  Fixed in 4.0.0-rc4.

Loading...