Skip to content

Possible XSS bug #1531

Description

@billford

Describe the bug
Create or edit a page
Steps To Reproduce
Steps to reproduce the behavior:

  1. create or edit a page
  2. add some text hit enter
  3. add malicious or even innocuous javascript
  4. you get the pop up on save or any refresh.

Expected behavior
This should be filtered and sanitized so it doesn't actually execute.

Screenshots
Attached
Screen Shot 2019-07-10 at 1 36 16 PM

Screen Shot 2019-07-10 at 1 36 02 PM

Your Configuration (please complete the following information):

  • Exact BookStack Version (Found in settings): BookStack v0.26.2

  • PHP Version: 7.2.19

  • Hosting Method (Nginx/Apache/Docker): Apache

Additional context
I have none.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions