View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
18236 | Bug reports | Survey participants (Tokens) | public | 2022-07-05 09:07 | 2022-07-05 15:04 |
Reporter | DenisChenu | Assigned To | |||
Priority | none | Severity | minor | ||
Status | confirmed | Resolution | open | ||
Product Version | 3.28.x | ||||
Summary | 18236: XSS: Unable to use attribute in URL | ||||
Description | When try to use ATTRIBUTE in URL, it was rewritten and broke the link | ||||
Steps To Reproduce | Steps to reproduceWith an user with XSS activated, disable HTML inline editor (can stay but more simple without) Expected result
Actual resultbecome | ||||
Tags | No tags attached. | ||||
Bug heat | 4 | ||||
Complete LimeSurvey version number (& build) | 3.28.17 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | not relevant | ||||
Database type & version | not relevant | ||||
Server OS (if known) | not relevant | ||||
Webserver software & version (if known) | not relevant | ||||
PHP Version | not relevant | ||||
child of | 09300 | closed | DenisChenu | XSS protection or variable substitution breaks links or other elements that contain variable substitutions |
We fix partially here : https://bugs.limesurvey.org/view.php?id=9300 ( XSS protection or variable substitution breaks links or other elements that contain variable substitutions) Maybe we can allow _ ? Feature or bug ? |
|
I would say is a bug, but I would set a low priority right now. |
|
Confirming the issue as it was registered by Denis |
|
We have a fix to allow {QCODE} i think we must allow {QCODE_SUBQ} and {ATTRIBUTE_1} Tottaly OK for the low priority. About {TOKEN:ATTRIBUTE_1} : moire difficult : <code>:</code> is encoded too … |
|
Not sure I follow.
Not following, sorry. |
|
No the issue is : XSS: Unable to use attribute in URL Follow parent link |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2022-07-05 09:07 | DenisChenu | New Issue | |
2022-07-05 09:07 | DenisChenu | Relationship added | child of 09300 |
2022-07-05 09:08 | DenisChenu | Note Added: 70696 | |
2022-07-05 09:08 | DenisChenu | Bug heat | 0 => 2 |
2022-07-05 14:47 | gabrieljenik | Note Added: 70717 | |
2022-07-05 14:47 | gabrieljenik | Bug heat | 2 => 4 |
2022-07-05 14:47 | gabrieljenik | Assigned To | => gabrieljenik |
2022-07-05 14:47 | gabrieljenik | Status | new => confirmed |
2022-07-05 14:47 | gabrieljenik | Note Added: 70718 | |
2022-07-05 14:49 | DenisChenu | Note Added: 70719 | |
2022-07-05 14:57 | gabrieljenik | Note Added: 70723 | |
2022-07-05 15:03 | DenisChenu | Note Added: 70726 | |
2022-07-05 15:03 | gabrieljenik | Assigned To | gabrieljenik => |
2022-07-05 15:04 | DenisChenu | Note Edited: 70726 |