New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 906658 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 7
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug


Participants' hotlists:
asd


Sign in to add a comment

"><svg/onload=alert(1);>

Reported by keremtam...@gmail.com, Nov 19

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36

Steps to reproduce the problem:
1. asd
2. asd
3. "><svg/onload=alert(1);>

What is the expected behavior?
asd

What went wrong?
asd

WebStore page: "><svg/onload=alert(1);>

Did this work before? N/A 

Chrome version: 70.0.3538.102  Channel: stable
OS Version: 10.0
Flash Version: "><svg/onload=alert(1);>

"><svg/onload=alert(1);>
 
svg.svg
286 bytes Download
"><svg/onload=alert(1);>
asdas
svg.jpg
286 bytes View Download
asdasd
svg.svg
286 bytes Download
<h1>TEST</h1>
asdasdasd
svg.svg
286 bytes Download
Labels: Needs-Triage-M70
Cc: krajshree@chromium.org
Labels: Needs-Feedback Triaged-ET
reporter@ - Thanks for filing the issue...!!

Could you please provide detailed manual reproducible steps with expected and actual results to test the issue from TE-end. Also please provide a sample test file/url to test the issue from TE-end. This will help us in triaging the issue further.

Thanks...!!
Status: WontFix (was: Unconfirmed)
Mac triage: WontFix - this is someone attempting to XSS the bug tracker, not a real bug.

Sign in to add a comment