View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 18236 | Bug reports | Survey participants (Tokens) | public | 2022-07-05 09:07 | 2022-07-05 15:04 |
| Reporter | DenisChenu | Assigned To | |||
| Priority | none | Severity | minor | ||
| Status | confirmed | Resolution | open | ||
| Product Version | 3.28.x | ||||
| Summary | 18236: XSS: Unable to use attribute in URL | ||||
| Description | When try to use ATTRIBUTE in URL, it was rewritten and broke the link | ||||
| Steps To Reproduce | Steps to reproduceWith an user with XSS activated, disable HTML inline editor (can stay but more simple without) Expected result
Actual resultbecome | ||||
| Tags | No tags attached. | ||||
| Bug heat | 4 | ||||
| Complete LimeSurvey version number (& build) | 3.28.17 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | not relevant | ||||
| Database type & version | not relevant | ||||
| Server OS (if known) | not relevant | ||||
| Webserver software & version (if known) | not relevant | ||||
| PHP Version | not relevant | ||||
| child of | 09300 | closed | DenisChenu | XSS protection or variable substitution breaks links or other elements that contain variable substitutions |
|
We fix partially here : https://bugs.limesurvey.org/view.php?id=9300 ( XSS protection or variable substitution breaks links or other elements that contain variable substitutions) Maybe we can allow _ ? Feature or bug ? |
|
|
I would say is a bug, but I would set a low priority right now. |
|
|
Confirming the issue as it was registered by Denis |
|
|
We have a fix to allow {QCODE} i think we must allow {QCODE_SUBQ} and {ATTRIBUTE_1} Tottaly OK for the low priority. About {TOKEN:ATTRIBUTE_1} : moire difficult : <code>:</code> is encoded too … |
|
Not sure I follow.
Not following, sorry. |
|
No the issue is : XSS: Unable to use attribute in URL Follow parent link |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2022-07-05 09:07 | DenisChenu | New Issue | |
| 2022-07-05 09:07 | DenisChenu | Relationship added | child of 09300 |
| 2022-07-05 09:08 | DenisChenu | Note Added: 70696 | |
| 2022-07-05 09:08 | DenisChenu | Bug heat | 0 => 2 |
| 2022-07-05 14:47 | gabrieljenik | Note Added: 70717 | |
| 2022-07-05 14:47 | gabrieljenik | Bug heat | 2 => 4 |
| 2022-07-05 14:47 | gabrieljenik | Assigned To | => gabrieljenik |
| 2022-07-05 14:47 | gabrieljenik | Status | new => confirmed |
| 2022-07-05 14:47 | gabrieljenik | Note Added: 70718 | |
| 2022-07-05 14:49 | DenisChenu | Note Added: 70719 | |
| 2022-07-05 14:57 | gabrieljenik | Note Added: 70723 | |
| 2022-07-05 15:03 | DenisChenu | Note Added: 70726 | |
| 2022-07-05 15:03 | gabrieljenik | Assigned To | gabrieljenik => |
| 2022-07-05 15:04 | DenisChenu | Note Edited: 70726 |