Skip to content

Conversation

hshpy
Copy link
Contributor

@hshpy hshpy commented Jul 28, 2025

identifier有注入风险。
poc:
/i/LyU0MCUzQ3glM0FzY3JpcHQlMjB4bWxucyUzQXglM0QlMjJodHRwJTNBJTJGJTJGd3d3LnczLm9yZyUyRjE5OTklMkZ4aHRtbCUyMiUzRWFsZXJ0KDEpJTNDJTJGeCUzQXNjcmlwdCUzRQ==

Co-authored-by: MadDogOwner <[email protected]>
Signed-off-by: ILoveScratch <[email protected]>
@ILoveScratch2 ILoveScratch2 requested a review from xrgzs July 28, 2025 14:43
Copy link
Member

@xrgzs xrgzs left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

复现成功,但缺少设备测试,不清楚此修复是否会破坏原有功能

@ILoveScratch2
Copy link
Member

复现成功,但缺少设备测试,不清楚此修复是否会破坏原有功能

只看代码来说没问题,但是没有实机测试

@hshpy
Copy link
Contributor Author

hshpy commented Jul 28, 2025

复现成功,但缺少设备测试,不清楚此修复是否会破坏原有功能

我也没设备测试(本来想用html/template,结果xml文档第一个<就转义了),只在原来的代码上改,应该没问题。

@elysia-best
Copy link
Contributor

应该没问题,经测试可以唤起安装,因为咱的测试环境没有https被拒绝了

@elysia-best elysia-best merged commit 11cf561 into OpenListTeam:main Jul 29, 2025
8 of 12 checks passed
@hshpy hshpy deleted the fix5 branch July 29, 2025 13:14
Suyunmeng pushed a commit that referenced this pull request Jul 30, 2025
* fix(security): potential XSS vulnerabilities

* chore: replace alist identifier to openlist identifier

Co-authored-by: MadDogOwner <[email protected]>
Signed-off-by: ILoveScratch <[email protected]>

---------

Signed-off-by: ILoveScratch <[email protected]>
Co-authored-by: ILoveScratch <[email protected]>
Co-authored-by: MadDogOwner <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants