Incomplete comment showing in comments tab in profile
Expected behavior
When I write a comment like the following Good <insert-timezone> it should be rendered in the comments tab into my profile.
Actual behavior
Writing this comment: "Good <insert-timezone>", is previewed as only "Good" in the comments tab into the profile.
How to reproduce
Doing it in your own:
- Go to any post.
- Comment the following in this post: Good <insert-timezone>
- Go to your profile and click in the comments tab.
Doing it by using my profile as an example:
- Go to my comment: Click to see the comment
- Now go to the comments in my profile Click to go to profile
- Comment is only "Good" instead of Good <insert-timezone>
Environment
- Browser: Google Chrome Version 63.0.3239.132 (Official Build) (64-bit)
- Operating system: macOS High Sierra
Visual Reproduction of the bug
Here is a GIF showing a visual production of this bug
Posted on Utopian.io - Rewarding Open Source Contributors
Hey @jaysermendez I am @utopian-io. I have just upvoted you!
Achievements
Suggestions
Get Noticed!
Community-Driven Witness!
I am the first and only Steem Community-Driven Witness. Participate on Discord. Lets GROW TOGETHER!
Up-vote this comment to grow my power and help Open Source contributions like this one. Want to chat? Join me on Discord https://discord.gg/Pc8HG9x
keep sharing, more power!
Thank you for the contribution. It has been approved.
Very nice finding.
At first it was steemit doesnt let you pass html tags in posts/comments. You somehow managed to bypass that by adding
-
Very well. @justyy check this out.original bug here
i think they need to recheck their regex.
You can contact us on Discord.
[utopian-moderator]
Yup! Regex was bypassed by simply adding a dash into the tag. It can lead to XSS! Thanks
I think this happens to busy.org as well...
It happens in all of them. Should I made a report for each one? Haha
Nvm u did it