VULNERABILITY DETAILS
Chrome is rendering unencoded version of URI when using document.write(document.baseURI); This is not expected behavior and Firefox renders encoded characters in that case.
Please have a look into it.
VERSION
Chrome Version: 60.0.3112.101 (Official Build) (64-bit)
Operating System: Windows 7 Professional
REPRODUCTION CASE
To reproduce on local please try: file:///C:/Users/abcde/Desktop/test.html#test<strong>test</strong>
I've also placed that on gist https://gistpreview.github.io/?4ce86a5183bb8317c91dbbb1839c3a4f#test<strong>test</strong>
---
Further thoughts:
- oddly enough when you do #test<script>alert('xss');</script> it'll get blocked with: ERR_BLOCKED_BY_XSS_AUDITOR
- it's tricky to say without doubt whether it's a chrome or javascript security issue then since some strings are blocked by auditor it could be that you'd like to have the values urlencoded
|
Deleted:
test.html
110 bytes
|
|
Deleted:
reproduced.png
21.6 KB
|
Comment 1 by elawrence@chromium.org
, Aug 24 2017Status: Untriaged (was: Unconfirmed)