New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 636970 link

Starred by 6 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac
Pri: 3
Type: Bug



Sign in to add a comment

base href removed if textarea with name attribute have a-tag and POST

Reported by hur...@gmail.com, Aug 11 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/51.0.2704.79 Chrome/51.0.2704.79 Safari/537.36

Example URL:
https://github.com/larvit/chromebug

Steps to reproduce the problem:
1. See git-repo
2. 
3. 

What is the expected behavior?
base href should remain intact (in the example being "/")

What went wrong?
base href gets removed to an empty string ""

Does it occur on multiple sites: Yes

Is it a problem with a plugin? No 

Did this work before? N/A 

Does this work in other browsers? Yes 

Chrome version: 51.0.2704.79  Channel: stable
OS Version: Ubuntu 16.04 64-bit
Flash Version: 

Tested in Firefox and it works there. Not tested in other browsers.
 
Components: -Blink Blink>Forms

Comment 2 by tkent@chromium.org, Aug 11 2016

Components: -Blink>Forms Blink>SecurityFeature
Sounds like an XSSAuditor issue.

Comment 3 by mkwst@chromium.org, Feb 14 2017

Labels: -Pri-2 OS-Android OS-Chrome OS-Mac OS-Windows Pri-3
Owner: tsepez@chromium.org
Status: Assigned (was: Unconfirmed)
It does flag the POST as an XSS Auditor violation. Tom, WDYT?

Comment 4 by mkwst@chromium.org, Feb 23 2017

 Issue 485291  has been merged into this issue.

Comment 5 by mkwst@chromium.org, Feb 23 2017

Issue 612672 has been merged into this issue.

Comment 6 by mkwst@chromium.org, Feb 23 2017

Cc: vyalla@chromium.org
 Issue 161845  has been merged into this issue.

Comment 7 by mkwst@chromium.org, Feb 23 2017

Cc: abarth@chromium.org
 Issue 312968  has been merged into this issue.

Comment 8 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt

Comment 9 by est...@chromium.org, Feb 18 2018

Labels: -Hotlist-EnamelAndFriendsFixIt

Sign in to add a comment