Skip to content

Fix XSS vulnerability in block label input#506

Open
karthik-dev56 wants to merge 1 commit intosugarlabs:masterfrom
karthik-dev56:fix-xss-vulnerability-block-labels
Open

Fix XSS vulnerability in block label input#506
karthik-dev56 wants to merge 1 commit intosugarlabs:masterfrom
karthik-dev56:fix-xss-vulnerability-block-labels

Conversation

@karthik-dev56
Copy link
Copy Markdown

The vulnerability allowed XSS attacks through unsanitized labelValue in number block innerHTML assignment. This fix extends the existing safetext() sanitization that was already applied to text blocks.

- Apply HTML sanitization to number block labels using safetext()
- Ensures consistent security across both text and number block inputs
- Prevents injection of malicious JavaScript via block label editing
- Resolves issue sugarlabs#505

The vulnerability allowed XSS attacks through unsanitized labelValue
in number block innerHTML assignment. This fix extends the existing
safetext() sanitization that was already applied to text blocks.
@walterbender
Copy link
Copy Markdown
Member

I am a bit confused. It seems you are working from a very outdated branch. Can you rebase from current master?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants