Skip to content

Conversation

@mgburns
Copy link
Contributor

@mgburns mgburns commented Feb 10, 2025

Changes

  • Adds input sanitization before using $_GET['tab'] to fix XSS vulnerability

How To Test

  1. Confirm that this link doesn't pop up an alert:

https://mozilla-builders-wp.ddev.site/programs/?tab=cohorts%22%3E%3Csvg%2fonload=alert(document.domain)%3e

(as it does here)

@mgburns mgburns self-assigned this Feb 10, 2025
@mgburns mgburns requested a review from braican February 10, 2025 18:17
@mgburns mgburns merged commit e9d968d into main Feb 10, 2025
1 check passed
@mgburns mgburns deleted the fix-xss-vulnerability branch February 10, 2025 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants