Security report: links redirection parsing error

in #utopian-io6 years ago (edited)

This issue follows the issue: https://github.com/busyorg/busy/issues/1492

Expected behavior

All external links are open in a new tab so users notice their are changing website.
busy.org/@cryptohazard should open in the same tab while steemit.com/@cryptohazard opens in a new tab.

Actual behavior

There is an error in the way you parse the link. I can bypass your security by putting busy.org in the beginning of the url and it will open in the same tab.

How to reproduce

I made a post on busy.org to test the issue:
https://busy.org/@cryptohazard/security-tests



Posted on Utopian.io - Rewarding Open Source Contributors

Sort:  

Coin Marketplace

STEEM 0.19
TRX 0.13
JST 0.029
BTC 58728.31
ETH 3185.59
USDT 1.00
SBD 2.43