summaryrefslogtreecommitdiffstats
path: root/shard.lock
diff options
context:
space:
mode:
authorSamantaz Fox <coding@samantaz.fr>2021-12-19 20:11:50 +0100
committerSamantaz Fox <coding@samantaz.fr>2021-12-19 20:51:44 +0100
commitddb06b0cac4c0b78e2e8e085791bce4c3a760625 (patch)
tree65329c6b0b6cc616d511b63cfe4632a0a4ee3218 /shard.lock
parent2ac19eb8fce69222a94f7bd9b6dc1e5027341111 (diff)
downloadinvidious-ddb06b0cac4c0b78e2e8e085791bce4c3a760625.tar.gz
invidious-ddb06b0cac4c0b78e2e8e085791bce4c3a760625.tar.bz2
invidious-ddb06b0cac4c0b78e2e8e085791bce4c3a760625.zip
Fix XSS vulnerability in channel playlists
The channel/<ucid>/playlists page was vulnerable to Cross Site Scripting (XSS), because the different URL parameters were inserted as-is in the URL meant for instance switching. This vulnerability could allow an attacker to inject malicious Javascript in the page by tricking the user to click on a crafted link. Bug introduced in commit 66e7285108363c3c3dcb814bdffb716c14e1724d ("Only use /redirect when automatically redirecting"). Thanks to Jack (@testa:cthd.icu on Matrix, @cysea on github) for responsibly reporting this issue!
Diffstat (limited to 'shard.lock')
0 files changed, 0 insertions, 0 deletions