-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Labels
priority:highThis is a high-priority issueThis is a high-priority issueproject:jsThis affects the js UIThis affects the js UItag:securityThis is a security issue (encryption problem, data leak, etc)This is a security issue (encryption problem, data leak, etc)type:bugGET THE RAIDGET THE RAID
Milestone
Description
Notes allow <meta>
tag injection. Ie, a note with the content
<META HTTP-EQUIV="refresh" CONTENT="0; URL=https://google.com">
opens a new browser window to Google. While this problem would happen over person-to-person sharing and thus the severity is limited (because you generally only share with those you trust) it remains high priority.
Special thanks to Rafay Baloch and Muhammad Samak for this report.
Metadata
Metadata
Assignees
Labels
priority:highThis is a high-priority issueThis is a high-priority issueproject:jsThis affects the js UIThis affects the js UItag:securityThis is a security issue (encryption problem, data leak, etc)This is a security issue (encryption problem, data leak, etc)type:bugGET THE RAIDGET THE RAID