JLyne / LiveAtlas

A Dynmap, Squaremap, Pl3xmap and Overviewer frontend for the modern web
Apache License 2.0
336 stars 37 forks source link

Nasty JavaScript execution from minecraft chat #638

Closed RealFX-Code closed 8 months ago

RealFX-Code commented 8 months ago

I managed to execute JavaScript from a game client to the browser. This was incredibly easy to do and could be easily exploited from a malicious user.

https://github.com/JLyne/LiveAtlas/assets/25106569/1ccb6f31-6a48-4174-8fb2-49f535111efb

JLyne commented 8 months ago

Oops, was under the impression dynmap escaped chat messages like it does with markers. Fixed.