persistent xss on code.launchpad.net

Bug #911632 reported by David
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
Critical
Richard Harding

Bug Description

A user's full name is shown un-escaped on their code.launchpad.net profile page thus providing a persistent xss vector.
For example, the user I just created with the username "ohnoes" and full name "/><script>alert(3);</script> profile can be found at
https://code.launchpad.net/~ohnoes (by going to that page you will see an alert box with the number 3 in it).

Tags: qa-ok

Related branches

William Grant (wgrant)
Changed in launchpad:
importance: Undecided → Critical
status: New → Triaged
Changed in launchpad:
assignee: nobody → Richard Harding (rharding)
status: Triaged → In Progress
Revision history for this message
Launchpad QA Bot (lpqabot) wrote :
tags: added: qa-needstesting
Changed in launchpad:
status: In Progress → Fix Committed
William Grant (wgrant)
tags: added: qa-ok
removed: qa-needstesting
Steve Kowalik (stevenk)
Changed in launchpad:
status: Fix Committed → Fix Released
David (d--)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.