xss vulnerability in new bug subscription overlay

Bug #740640 reported by Diogo Matsubara
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
Critical
Данило Шеган

Bug Description

The field to name a new bug subscription filter doesn't escape html properly

Steps to reproduce:
1. Open https://launchpad.dev/firefox
2. Click the "+ Subscribe to bug mail" link
3. Enter </script><script>javascript:alert('XSS')</script><script> as the Subscription name.
4. Save the changes.
5. Open https://launchpad.dev/firefox/+subscriptions

What happens:

You get the XSS javascript alert

What should happen:

The html tags should've been properly escaped.

This was tested on lp:~yellow/launchpad/accordionoverlay

Related branches

description: updated
Changed in launchpad:
assignee: nobody → Launchpad Yellow Squad (yellow)
Changed in launchpad:
assignee: Launchpad Yellow Squad (yellow) → Данило Шеган (danilo)
status: Triaged → In Progress
Revision history for this message
Launchpad QA Bot (lpqabot) wrote :
Changed in launchpad:
milestone: none → 11.04
tags: added: qa-needstesting
Changed in launchpad:
status: In Progress → Fix Committed
Revision history for this message
Robert Collins (lifeless) wrote :

This is all behind a feature flag - no impact on production

tags: added: qa-untestable
removed: qa-needstesting
William Grant (wgrant)
Changed in launchpad:
status: Fix Committed → Fix Released
William Grant (wgrant)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.