Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Search for XSS vulnerabilities in the vault #28

Closed
UzJu opened this issue Oct 23, 2024 · 4 comments
Closed

[BUG] Search for XSS vulnerabilities in the vault #28

UzJu opened this issue Oct 23, 2024 · 4 comments

Comments

@UzJu
Copy link

UzJu commented Oct 23, 2024

# Description error

Briefly describe the mistakes.

<! -only open the community plug-in in the new vault to reproduce->

# Reproduction step

  1. Go to " ...
    Create a new md file and then write the following characters.
echo '<img src=https://crowdshield.com/.testing/xss.js onload=prompt(2) onerror=alert(3)></img>'// XXXXXXXXXX
  1. Click' ...' 3.
    Then use the function of search in vault.
  2. Scroll down to " ....
  3. Check the errors
image image

# Expected behavior

Briefly describe what you expect to happen.

<! -optional->

# screenshot

If applicable, please add screenshots to help explain your problem.

# Environment

  • OS:
  • Obsidian Version:
    -Plug-in version: latest
@yan42685
Copy link
Owner

Thanks for reminding me. I'll cope with it this week.

@yan42685
Copy link
Owner

yan42685 commented Oct 24, 2024

Fixed in 0.2.11 😃

I deleted a thoughtless reply, please ignore it.

@UzJu
Copy link
Author

UzJu commented Oct 25, 2024

Hello:) Thanks again for such a great plugin for Obsidian, I've re-tested the fix version and the issue has been fixed, no new issues found.

It's ok, because my main job is security research, I have some attack payloads inside my notes, and then one time I queried it, I triggered the issue by chance, so I'll give you the first feedback.

Thanks again for such a great plugin and have a nice life!

@yan42685
Copy link
Owner

Hello! I'm glad to know you recognize the value of this plugin, and I appreciate your feedback. If you need anything in the future, feel free to reach out. Wishing you all the best in your security research. Have a wonderful weekend!

@UzJu UzJu closed this as completed Oct 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants