FORM POST with input type="text" and value contains iframe
Reported by
vajon...@gmail.com,
Apr 23 2018
|
||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36 Steps to reproduce the problem: 1. Insert a value that looks like this "<iframe ... ></iframe>" in input text or textarea. 2. Submit the POST to a new page display with the "<iframe ... ></iframe>" embedded. 3. As a result: ERR_BLOCKED_BY_XSS_AUDITOR What is the expected behavior? 1. Insert a value that looks like this "<iframe ... ></iframe>" in input text or textarea. 2. Submit the POST to a new display with the "<iframe ... ></iframe>" embedded. 3. Displays the page with "<iframe ... ></iframe>" included. Works with Mozilla Firefox and Microsoft Edge What went wrong? 1. As a result: ERR_BLOCKED_BY_XSS_AUDITOR 2. Using "reload this page" button. 3. Views the page with the requested result but PHP defined $_SESSION is damaged. Did this work before? N/A Does this work in other browsers? Yes Chrome version: 65.0.3325.181 Channel: stable OS Version: 10.0 Flash Version: If you need more info contact vajonny0@gmail.com
,
Apr 23 2018
,
Apr 24 2018
,
Apr 24 2018
A live example at: http://forum.virtual-haus.com/video_emb/ at the moment: //header("X-XSS-Protection: 0;");
,
Apr 24 2018
I do not think there is anything to do here, it does not seem to be a bug.
You are simply rendering whatever it is that the user is typing, even if they type <script>alert('')</script>.
I think you will have to add the header and be done with it, because this is exactly what the XSS auditor is designed to block.
@tsepez, any thoughts?
,
Apr 24 2018
OK, thanks! I will use it without XSS auditor for now ...
,
Apr 26 2018
|
||||
►
Sign in to add a comment |
||||
Comment 1 by phistuck@gmail.com
, Apr 23 2018