New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 709923 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Buried. Ping if important.
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

While submitting a form, showing error message "ERR_BLOCKED_BY_XSS_AUDITOR"

Reported by gaurav.p...@gmail.com, Apr 10 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36

Example URL:
qa.mad-learn.com

Steps to reproduce the problem:
1. Submit any form with this URL.
2. 
3. 

What is the expected behavior?
Chrome detected unusual code on this page and blocked it to protect your personal information (for example, passwords, phone numbers, and credit cards).
Try visiting the site's homepage.
ERR_BLOCKED_BY_XSS_AUDITOR

What went wrong?
After submitting the form it shows "Chrome detected unusual code on this page and blocked it to protect your personal information (for example, passwords, phone numbers, and credit cards). Try visiting the site's homepage. ERR_BLOCKED_BY_XSS_AUDITOR"

Does it occur on multiple sites: Yes

Is it a problem with a plugin? N/A 

Did this work before? N/A 

Does this work in other browsers? Yes

Chrome version: 57.0.2987.133  Channel: stable
OS Version: 10.0
Flash Version: Shockwave Flash 25.0 r0
 
Cc: brajkumar@chromium.org
Labels: Needs-Feedback
Gaurav@ - Could you please provide any test account to check this issue from Chrome-TE end or is there any option available to create an account ?

Thanks!
It is not an URL specific issue, it is happening with multiple sites. For now we have used <system.webServer>
<httpProtocol>
      <customHeaders>
        <add name="X-XSS-Protection" value="0" />
      </customHeaders>
    </httpProtocol>
  
  </system.webServer>

With the help of this configuration, issue is resolved.
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 11 2017

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "brajkumar@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 4 by junov@chromium.org, Apr 11 2017

Cc: mkwst@chromium.org
Components: -Blink Blink>HTML>Parser
Owner: mkwst@chromium.org
Status: Assigned (was: Unconfirmed)
Looks like a potential duplicate of  issue 683798 , which is fixed in Chrome 58.

Sign in to add a comment