wise-team / steemprojects.com

Steem Projects is a directory of apps, sites and tools build by Steem community
https://SteemProjects.com/
MIT License
26 stars 13 forks source link

Vulnerability on Steemprojects: The XSS without HTML: Client-Side Template Injection with AngularJS #147

Closed emirfirlar closed 6 years ago

emirfirlar commented 6 years ago

Project Information

Expected behavior

Defending 'The XSS without HTML: Client-Side Template Injection with AngularJS' Attack

Actual behavior

This script is vulnerable to 'The XSS without HTML: Client-Side Template Injection with AngularJS' attacks.

How to reproduce

     Cross site scripting (XSS) is an important vulnerability that allows an attacker to send malicious code to another user. 'Client-Side Template Injection with AngularJS' is a XSS without HTML. SteemProjects is vulnerable to AngularJS client-side template injection vulnerability. Malicious users may gather data with use this. The attackers can take over the account, impersonating the user.

https://SteemProjects.com/{{constructor.constructor('alert("====> XSS Found By emirfirlar <====")')()}}

Recording Of The Bug

![ezgif.com-video-to-gif (1).gif](https://steemitimages.com/DQmPjFxXhF981jFU5U2vjrNLV8xym1WRGEpLbovTSJCxzF6/ezgif.com-video-to-gif%20(1).gif)

![Ekran Alıntısı2.JPG](https://steemitimages.com/DQmW5QcBUv1wxNM6Xyq395DAbkwgMAnVQ9Sa4tdKBRvtMtP/Ekran%20Al%C4%B1nt%C4%B1s%C4%B12.JPG)

Proof of Work Done

https://github.com/emirfirlar

noisy commented 6 years ago

@emirfirlar - Thank you for reporting this!

Note: for sure, I should notice this issue earlier.