Skip to content
This repository has been archived by the owner on Sep 18, 2024. It is now read-only.

XSS Vulnerability caused by Redactor 3 #796

Open
shellsniper opened this issue Jul 5, 2018 · 3 comments
Open

XSS Vulnerability caused by Redactor 3 #796

shellsniper opened this issue Jul 5, 2018 · 3 comments

Comments

@shellsniper
Copy link

The stored XSS can be triggered once you editing content by using Redactor 3 (https://imperavi.com/redactor/) plugin. it can be found in both PAGE and BLOG modules.

image

To developer:
Please avoid use Redactor right now before they fix this issue.

Reference:
#794
https://imperavi.com/redactor/

@anupriya17
Copy link
Member

anupriya17 commented Jul 5, 2018 via email

@sandeepone
Copy link
Member

@anupriya17 I'll be looking into it right now.

sandeepone added a commit that referenced this issue Jul 5, 2018
Thanks for pointing the bug #794 #796. by @y-mehta @levoncf
@sandeepone
Copy link
Member

@levoncf @anupriya17 I've disabled Redactor immediately. Will investigate into further. Feel free to share your opinions

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants