Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork1.3k
Open
Labels
Milestone
Description
Describe the bug
Hi there!
There's an XSS vulnerability when you open your index.html if you saved a page with a title containing an XSS vector.
Steps to reproduce
- Save this page for example: [Twitter of @garethheyes] ](https://twitter.com/garethheyes/status/1126526480614416395)
- Open your index.html
- Get XSS'd by sir @garethheyes
Source code:
<a href="archive/1557816881/twitter.com/garethheyes/status/1126526480614416395.html" title="\u2028\u2029 op Twitter: "Another way to use throw without a semi-colon:<script>{onerror=alert}throw 1</script>"">
Software versions
- OS: ArchLinux
- ArchiveBox version: 903.59da482-1
- Python version: python3.7
- Chrome version: Chromium 74.0.3729.131 Arch Linux