Dec 7th 2022


XSS Vulnerability in the Events and Markdown features

Proof of Concept

  1. Login to the dashboard

  2. Insert or Edit Events in the Description and Link

  3. Payload like that

[Link](data:text/html,s<script>alert(1) </script>)






Run Javascript Code on User Browser

Sylvain Jermini validated this vulnerability a year ago

hi @reza.duty , I mark this issue as Valid. It should be noted it must be done by the admin/event creator itself and it should preview the data and click the link, which is quite a contrived scenario, but anyway, good catch! We appreciate it.

We already did a fix by filtering out any non http / https protocols, which should handle this specific case.

Thank you.

Sylvain Jermini marked this as fixed in Alf.io 2.0-M4-2301 with commit 21cb28 a year ago
