Skip to content
This repository was archived by the owner on Dec 19, 2023. It is now read-only.

FIX: Filter bypass leading to XSS#1

Closed
v1dhun wants to merge 5 commits into418sec:masterfrom
v1dhun:V1dhun-patch-regex
Closed

FIX: Filter bypass leading to XSS#1
v1dhun wants to merge 5 commits into418sec:masterfrom
v1dhun:V1dhun-patch-regex

Conversation

@v1dhun
Copy link
Copy Markdown

@v1dhun v1dhun commented May 1, 2020

❓ Technical description

Filter bypass leading to XSS

🐛 Proof of Vulnerability (PoV)

trentm#348

🔥 Proof of Fix (PoF)

Screenshot_2020-05-03 AL XSS Catcher - Regex Tester Debugger

@v1dhun
Copy link
Copy Markdown
Author

v1dhun commented May 4, 2020

Hi @huntr-helper, any update on this?

@JamieSlome
Copy link
Copy Markdown

JamieSlome commented May 5, 2020

Hi @v1dhun - your pull request will be reviewed at the end of the week when the team does bounty reviews! 🍰

Although, it does seem that this issue may have already been addressed externally: trentm#348 🎉

@JamieSlome
Copy link
Copy Markdown

JamieSlome commented May 8, 2020

After reviewing the issue (trentm#348) it looks like a fix has already been accepted (trentm#353).

Thank you! 🍰

@JamieSlome JamieSlome self-requested a review May 8, 2020 09:08
Copy link
Copy Markdown

@JamieSlome JamieSlome left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very nice usage of the template :)

In this instance, a fix was already provided to the root repository: trentm#353

Thanks! 🍰

@huntr-helper
Copy link
Copy Markdown

Sorry @v1dhun, we enjoyed reviewing your fix but it has not been selected this time. If this bounty has not been closed, please feel free to try again with a new pull request! We appreciate your effort and look forward to reviewing more of your fixes in the future! 🔨 😎

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants