Critical vulnerability XSS (Cross Site Scripting) Steemnova (fixed)

in #utopian-io8 years ago (edited)

Expected behavior

When I play the browser game SteemNova, I expect that I can play a game that is free of dangerous security vulnerabilities. In particular, I expect that there is no vulnerability that can endanger other players in the game or introduce malware on a computer.

Actual behavior

Unfortunately I discovered a security hole that can not only affect the game but can also be dangerous for other players of the game. The vulnerability found is an XSS (Cross-Site Scripting) vulnerability and can be set in the area of an alliance administration. Since there is an editor (TinyMCE) here that allows this vulnerability to be infiltrated.

A big thank you goes to the developer team and the project owner who took care of this vulnerability at short notice and have already implemented it in the live system. This went so far without big problems about which I am very happy.

How to reproduce

The problem has now been resolved. It was previously possible to reload malware with Javascript if you used this command among others. (demonstration)

[url=javascript:alert(String.fromCharCode(88,83,83))]http://google.com/[/url]
  • Browser: Chrome Version 65.0.3325.146 (Offizieller Build) (64-Bit)
  • Operating system: Mac os x

Recording Of The Bug

Demonstration.
enter image description here

Thanks to the project leaders and developers who solved the problem very quickly!
@louis88



Posted on Utopian.io - Rewarding Open Source Contributors

Sort:  

Thank you for the contribution. It has been approved.

Thank you for the professional way you've dealt with this issue. I can't make sure the bug was real, but I'm more than happy to take your's and @mys's word for it.

You can contact us on Discord.
[utopian-moderator]

Hey @jestemkioskiem, I just gave you a tip for your hard work on moderation. Upvote this comment to support the utopian moderators and increase your future rewards!

Thank You for finding and fixing this security flaw! Both @louis88 and @MWFIAE who cooperated to make a patch. As You said the critical update has been implement asap so that nobody got hurt. Thanks!

Thank you for treating the whole thing with the necessary seriousness!
And for the fact that we were able to fix it so quickly and frictionless :)

Loading...

Hey @louis88 I am @utopian-io. I have just upvoted you!

Achievements

  • You have less than 500 followers. Just gave you a gift to help you succeed!
  • Seems like you contribute quite often. AMAZING!

Suggestions

  • Contribute more often to get higher and higher rewards. I wish to see you often!
  • Work on your followers to increase the votes/rewards. I follow what humans do and my vote is mainly based on that. Good luck!

Get Noticed!

  • Did you know project owners can manually vote with their own voting power or by voting power delegated to their projects? Ask the project owner to review your contributions!

Community-Driven Witness!

I am the first and only Steem Community-Driven Witness. Participate on Discord. Lets GROW TOGETHER!

mooncryption-utopian-witness-gif

Up-vote this comment to grow my power and help Open Source contributions like this one. Want to chat? Join me on Discord https://discord.gg/Pc8HG9x

Coin Marketplace

STEEM 0.08
TRX 0.29
JST 0.036
BTC 102204.93
ETH 3426.30
USDT 1.00
SBD 0.55