sasanrose / phpredmin

Yet another web interface for Redis
BSD 3-Clause "New" or "Revised" License
404 stars 96 forks source link

XSS-Vulnerability #98

Open MRH4287 opened 5 years ago

MRH4287 commented 5 years ago

I just noticed a strange behaviour. I added an Entry to Redis with the following Key:

<global>:....

When i opened PhpRedmin, i only saw :....

When opened in Dev-Tools i saw this: image

This can be used for XSS-Attacks.

I am using the Docker Version: Docker 17.03.1-ee-2 on linux, amd64 Image ID: sha256:3d3d15923fbb4e52dda1d6c53643b0d1ff584fa08b845c51f3bba7e7fb964a80