You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reported by skyice on 14 Apr 2014 12:06 UTC as Trac ticket #1489806
Hello,
When you use the check-spelling with non-html editor, you have an input where you can write something
[you add in the input something like that :
<img src="x"onerror="alert(/xss/)"/>
So what? You can only XSS yourself with this. When ending spell checking mode, that's turned into regular text. Not very nice but no harmful content is being sent to others from this.
Reported by skyice on 14 Apr 2014 12:06 UTC as Trac ticket #1489806
Hello,
When you use the check-spelling with non-html editor, you have an input where you can write something
[you add in the input something like that :
<img src="x"onerror="alert(/xss/)"/>
A popup will appear :
[[Image(http:_skyice.fr/images/popup.PNG)]([Image(http:_skyice.fr/images/input.PNG)]]
If)]
Migrated-From: http://trac.roundcube.net/ticket/1489806
The text was updated successfully, but these errors were encountered: