LuRenJiasWorld / WP-Editor.md

或许这是一个WordPress中最好,最完美的Markdown编辑器
https://wordpress.org/plugins/wp-editormd/
GNU General Public License v3.0
746 stars 87 forks source link

[BUG] xss漏洞 #507

Closed hakuQAQ closed 3 years ago

hakuQAQ commented 3 years ago

BUG描述 | Describe the bug

请清晰描述BUG的行为 A clear and concise description of what the bug is.

markdown代码块里的代码能逃逸出html编码,造成xss漏洞

复现方法 | To Reproduce

你是如何复现此BUG的,最好附带上能复现此BUG的文章地址或Markdown原文(建议使用PastebinGist上传) Steps to reproduce the behavior: Attached with link address of the post or plain Markdown text (Recommend using Pastebin or Gist) will be better.

文章地址:http://47.110.251.39/wordpress/index.php/2020/11/25/test/

markdown原文如下 image

期望行为 | Expected behavior

请描述你认为该功能的期望行为 A clear and concise description of what you expected to happen.

修复叭

截图 | Screenshots

详细的截图能帮助我们更好分析并重现此问题 If applicable, add screenshots to help explain your problem. image

LuRenJiasWorld commented 3 years ago

你好,这是一个已知问题,预计将于下一版本发布修复。我稍后尝试一下在最新版本和开发分支复现此问题。

hakuQAQ commented 3 years ago

okok