Closed utybo closed 3 years ago
The issue has been fixed.
All HTML tags are now stripped in news title, content, tags and signature. This fix also applies to previews on the homepage and on the newsgroup details page.
Thanks for the quick action. I'll close both this issue and the PR :)
RTFN is subject to XSS. Please remove it from the links ASAP.
I have no way of reaching out to the creators, please link me a repo somewhere where I could report this properly.I have contacted one of the creators by e-mail, but RTFN does not seem to be actively maintained, so I do not have high hopes that this will get resolved in a timely manner.Proof
What is even worse is that you have no way to know whether an article is malicious other than checking the page's source code,
<script>
blocks are invisible.Although usernames are logged within RTFN's systems, it is very easy through social engineering to get a user's credentials. And even then, exploiting this vulnerability is trivial.
Quick calculations on the CVSS 3.1 calculator indicate a juicy High (8.5/10) severity, yummy!