mirror of
https://github.com/NginxProxyManager/nginx-proxy-manager.git
synced 2026-04-25 09:25:55 +03:00
[GH-ISSUE #1950] Stored XSS when deleting proxy host #1415
Labels
No labels
awaiting feedback
bug
cannot reproduce
dns provider request
duplicate
enhancement
enhancement
enhancement
good first issue
help wanted
invalid
need more info
no certbot plugin available
product-support
pull-request
question
stale
troll
upstream issue
v2
v2
v2
v3
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/nginx-proxy-manager-NginxProxyManager#1415
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @l4rm4nd on GitHub (Mar 24, 2022).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/1950
Steps to reproduce:
<script>alert('XSS')</script>.google.comas domainRecommendation:
Implementing input validation and/or ensuring output sanitization as done for all other inputs/outputs.
Risk:
Low risk since high privileges are required.
@l4rm4nd commented on GitHub (Mar 24, 2022):
Also works for redirection hosts with XSS domain payloads. If a redirection host is deleted, XSS payload is executed.
@jc21 commented on GitHub (Mar 24, 2022):
Thanks for the pickup.
Fixed in
developbranch and will be out with the next release.