att / rcloud

Collaborative data analysis and visualization
http://rcloud.social
MIT License
432 stars 142 forks source link

encryption group names can be crafted for stored XSS in notebook info popup #2729

Closed gordonwoodhull closed 4 years ago

gordonwoodhull commented 4 years ago

It's possible to create a name for a group such that, when invoking notebook info for a notebook belonging to that group, will run bits of the group name as JS in the client.

gordonwoodhull commented 4 years ago

Notebook name in this popup was also vulnerable