Skip to content

Possible XSS in issue dependancies #5565

@zarunet

Description

@zarunet

Description

When adding an issue with an HTML tag in the title, said HTML doesn't seem to be escaped.

In this example, the <select> tag in the title is displayed as an actual <select>

2018-12-19_14-43-35

Metadata

Metadata

Assignees

No one assigned

    Labels

    topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions