HTML in Diffusion not escaped in certain circumstances
Unknown
Vulnerability Details
HTML in Diffusion source code listing is not escaped
Steps to reproduce:
* have the syntax hilight turned on
* the file is bigger than 256kB, thus syntax hilight is claimed in header to be turned off automatically, however, plaintext file doesn't display like with regular (manual) syntax highlight off, but the content is being parsed
File should contain HTML constructions, but could be of any type (extension).
Having javascript constructions there with alert() within the HTML causes such dialogues to pop up on given page obviously.
Actions
View on HackerOneReport Stats
- Report ID: 148865
- State: Closed
- Substate: resolved
- Upvotes: 12