Canvasbird / canvasboard

An interactive board with plugins focusing on replacing the need of multiple platforms for teaching, presenting, managing or explaining your ideas.
MIT License
198 stars 119 forks source link

Xss on Add New Workspace #350

Open mukeshpilaniya opened 3 years ago

mukeshpilaniya commented 3 years ago

Describe the bug πŸ› while adding a new workspace if a user type "><script>alert(1)</script> in the name field then the XSS is triggered on workspace.

To Reproduce Steps to reproduce the behavior:

  1. Go to 'https://canvasboard.live/'
  2. Click on 'Add New Workspace'
  3. Type Name as "><script>alert(1)</script>
  4. See error

Screenshots image

Additional context https://portswigger.net/web-security/cross-site-scripting

welcome[bot] commented 3 years ago

Hello there!πŸ‘‹ Welcome to the project!πŸš€βš‘

Thank you and congratsπŸŽ‰ for opening your very first issue in this project.Canvasboard is an interactive board with plugins focusing on replacing the need of multiple platforms for teaching, presenting or explaining your ideas. The interactive plugins are built using web technologies to ease your work right within a single platform. Please adhere to our Code of Conduct.πŸ™Œ You may submit a PR if you like, make sure to follow our Pull Request Template. If you want to report a bug🐞 please follow our Issue Template. Also make sure you include steps to reproduce it and be patient while we get back to you.πŸ˜„

Feel free to join our Slack Community.πŸ’– We have different channels for active discussions.✨ Hope you have a great time there!πŸ˜„