[Zappl] - XSS in search bar

Words
86
Reading
1 min
Listen
Play
9y

Expected behavior

XSS filter evasion should cover each edge case. All possible XSS code should be rejected.

Actual behavior

XSS filter evasion is not working for input text method, DIV expression method, and WAF ByPass Strings for XSS.

How to reproduce

Here are all the urls you can test to reflect the XSS bug:

https://gist.github.com/jayserdny/bf23a88197aabe2cbc5bae96fc31a198

Environment

  • Browser: Google Chrome Version 64.0.3282.186 (Official Build) (64-bit)
  • Operating system: macOS High Sierra

Some screenshots of the bug

Screen Shot 2018-03-13 at 2.21.11 AM.png
Screen Shot 2018-03-13 at 2.21.42 AM.png
Screen Shot 2018-03-13 at 2.22.06 AM.png
Screen Shot 2018-03-13 at 2.23.22 AM.png
Screen Shot 2018-03-13 at 2.23.51 AM.png
Screen Shot 2018-03-13 at 2.24.26 AM.png



Posted on Utopian.io - Rewarding Open Source Contributors

[Zappl] - XSS in search bar | Ecency