XSS vulnerability when prepopulating hidden fields

Created on 26 June 2023, over 1 year ago
Updated 27 June 2023, over 1 year ago

Steps to reproduce

Create a hidden field (ex. firstname), make sure Prepopulate is checked and add this to your url when viewing the webform: ?firstname=<img%20src=x%20onerror=alert(document.domain)>. In this case you will get an alert.

I don't have this issue when I want to prepopulate a regular (visible) field.

πŸ› Bug report
Status

Closed: outdated

Version

6.2

Component

Code

Created by

πŸ‡§πŸ‡ͺBelgium Seppe Beelprez

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024