New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 856767 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Last visit > 30 days ago
Closed: Jul 17
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug



Sign in to add a comment

Security: XSS in chromepmo.appspot.com

Reported by tthe.dol...@gmail.com, Jun 26 2018

Issue description

Hello,

I've found an XSS vulnerability in the domain chromepmo.appspot.com.
I guess that this has a very low priority and you will maybe not fix it but I still want to inform you about that bug. Feel free to close it and sorry If I am wasting your time.

POC: https://chromepmo.appspot.com/history/mstone?branch=master%3Cimg%20src=X%20onerror=alert(document.domain)%3E
 
Labels: -Type-Bug-Security Pri-1 Type-Bug
Owner: amineer@chromium.org
Status: Assigned (was: Unconfirmed)
No Sensitive info there, but should still fix it.

Alex, can you please fix an owner for this.
Status: WontFix (was: Assigned)
Thanks for the report.  Since inferno@ didn't escalate this, I'm going to assume it's not high priority from a security standpoint and the fix can wait a bit.  Given this, we're actively working to turn down the chromepmo.appspot.com application in favor of other tools, so this will be fixed once the chromepmo app is turned off.

Thus, I'm going to mark this as WontFix - but, thanks for taking the time to point out the issue, we really appreciate it!
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 24

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment