Page MenuHomePhabricator

Fix a self-XSS hole in Diffusion
ClosedPublic

Authored by epriestley on Mar 20 2015, 9:43 PM.
Tags
None
Referenced Files
F18877107: D12117.id.diff
Thu, Nov 6, 6:09 AM
F18875975: D12117.diff
Wed, Nov 5, 8:50 PM
F18781065: D12117.id29140.diff
Oct 12 2025, 9:16 PM
F18725702: D12117.id.diff
Sep 30 2025, 5:46 AM
F18721124: D12117.diff
Sep 29 2025, 8:36 PM
F18647212: D12117.diff
Sep 19 2025, 12:39 PM
F18411211: D12117.id.diff
Aug 30 2025, 5:45 AM
F18402419: D12117.diff
Aug 29 2025, 8:24 PM
Subscribers

Details

Reviewers
btrahan
chad
Commits
Restricted Diffusion Commit
rPac029d0a50e7: Fix a self-XSS hole in Diffusion
Summary

Via HackerOne. We aren't correctly escaping the date, so a user can XSS themselves by setting their date format creatively.

This construction is very unusual and I don't think we do anything similar elsewhere, so I can't come up with a systematic change which would prevent this in the general case.

Test Plan

Set date format to tag junk, got self-XSS before patch and proper escaping after the patch.

Diff Detail

Repository
rP Phabricator
Branch
xss1
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 4930
Build 4948: [Placeholder Plan] Wait for 30 Seconds

Event Timeline

epriestley retitled this revision from to Fix a self-XSS hole in Diffusion.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added reviewers: chad, btrahan.
chad edited edge metadata.
This revision is now accepted and ready to land.Mar 20 2015, 9:49 PM
This revision was automatically updated to reflect the committed changes.