Issue metadata
Sign in to add a comment
|
Security: xss in data:text/html
Reported by
0xak...@gmail.com,
Nov 30 2017
|
||||||||||||||||||||
Issue description
this is poc data:text/html;base64,PHNjcmlwdD5hbGVydCgiYWtyZW0iKTwvc2NyaXB0Pg==
poc ( <script>('alert')</script> ) into base64
,
Nov 30 2017
This isn't an XSS attack, it's simply a text document served via a data URI that contains script. This is working as expected, and does not give the "attacker" any permissions of interest (as the code runs from an anonymous origin).
,
Nov 30 2017
,
Mar 9 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by 0xak...@gmail.com
, Nov 30 201714.5 KB
14.5 KB View Download