[wp-trac] [WordPress Trac] #26350: <a href="&#106; avascript:alert('Successful XSS')">Click this link!</a>

WordPress Trac noreply at wordpress.org
Mon Mar 16 16:33:43 UTC 2020


#26350: <a href="javascript:alert('Successful XSS')">Click this link!</a>
----------------------------+-----------------------------------
 Reporter:  azaozz          |       Owner:  (none)
     Type:  defect (bug)    |      Status:  closed
 Priority:  high            |   Milestone:  5.5
Component:  Administration  |     Version:  3.8
 Severity:  major           |  Resolution:  invalid
 Keywords:                  |     Focuses:  ui, css, performance
----------------------------+-----------------------------------
Changes (by 01ahmd):

 * Attachment ""><img src=onerror="(1)">.png" added.

 <a href="javascript:alert('Successful XSS')">Click this link!</a>

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/26350>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list