Skip to content

Conversation

catnose99
Copy link
Contributor

There is a XSS vulnerability around error handling.
Here are some examples.

$$"<img/src=./ onerror=alert(location)>
e^{i\theta} = i\sin\thetae^{i\theta}
$$
$$
e^{i\theta"<img/src=./ onerror=alert(location)>} = \cos\theta + i\sin\thetae^{i\theta} 
$$

I made a change to escape tex string.

Thank you!

@catnose99 catnose99 changed the title fix: error message XSS risk fix: error message XSS vulnerability Sep 21, 2020
@snoopysecurity
Copy link

Hey @goessner, any chance you could review this PR and fix this XSS issue?

@goessner
Copy link
Owner

Hi @catnose99 ... thanks for fixing that critical vulnerability ... sorry for lasting so long, to be able to get active here again.

--

sg

@goessner goessner merged commit 596f786 into goessner:master May 24, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants