Skip to content
This repository has been archived by the owner on Sep 2, 2019. It is now read-only.

XSS in jQuery qeditor #12

Open
soaj1664 opened this issue Apr 13, 2014 · 0 comments
Open

XSS in jQuery qeditor #12

soaj1664 opened this issue Apr 13, 2014 · 0 comments

Comments

@soaj1664
Copy link

Hi,

The editor is vulnerable to an XSS. The editor allows users to insert link and if instead of normal link, I input JavaScript URI

javascript:alert%28location%29

then it works. The attacker can execute arbitrary code of his choice. Please fix this issue. Thanks

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant