Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bug: XSS test creates links that trigger XSS #1415

Closed
1 task done
Rho-9-Official opened this issue Sep 4, 2024 · 3 comments
Closed
1 task done

bug: XSS test creates links that trigger XSS #1415

Rho-9-Official opened this issue Sep 4, 2024 · 3 comments
Labels
bug Something isn't working

Comments

@Rho-9-Official
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

image Honestly this one explains it all, but I was scanning a site upon request, and found they're vulnerable to XSS....and so is Rengine

Expected Behavior

Expected behavior would be to display the URLs, with extra handling to account for the links having XSS payloads

Steps To Reproduce

scan an XSS vulnerable site like this one
image
when you go to view the vulnerabilities....have fun clicking out of several pop up boxes that got injected

Environment

- reNgine: 
- OS: 
- Python: 
- Docker Engine: 
- Docker Compose: 
- Browser:

Anything else?

No response

@Rho-9-Official Rho-9-Official added the bug Something isn't working label Sep 4, 2024
Copy link
Contributor

github-actions bot commented Sep 4, 2024

Hey @Rho-9-Official! 👋 Thanks for flagging this bug! 🐛🔍

You're our superhero bug hunter! 🦸‍♂️🦸‍♀️ Before we suit up to squash this bug, could you please:

📚 Double-check our documentation: https://rengine.wiki
🕵️ Make sure it's not a known issue
📝 Provide all the juicy details about this sneaky bug

Once again - thanks for your vigilance! 🛠️🚀

@yogeshojha
Copy link
Owner

Hi @Rho-9-Official do you mind submitting this via https://github.com/yogeshojha/rengine/security
It will be easier for me to manage security reports from there and maybe we could assign you a CVE ID as well.

Thanks

@yogeshojha
Copy link
Owner

Reported as security report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants