Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

false positive in url geolocation.com #114

Open
alechner opened this issue Nov 28, 2022 · 2 comments
Open

false positive in url geolocation.com #114

alechner opened this issue Nov 28, 2022 · 2 comments
Assignees

Comments

@alechner
Copy link

alechner commented Nov 28, 2022

What is this feature about (expected vs actual behaviour)?

Link url https://www.geolocation.com is not passing, also https://www.history.com

How can I reproduce it?

insert a link with one of the URLs above and it will report as it have xss

Does it take minutes, hours or days to fix?

don't know

Any additional information?

if the url have some string of (_never_allowed_js_callback_regex) plus a dot, it will report as positive.
this detection occurs in lines (1153-1161) of AntiXSS.php

@voku voku self-assigned this Nov 28, 2022
@voku
Copy link
Owner

voku commented Feb 11, 2023

Can you please provide an example, thanks.


Update: Good question, now I see the problem, I'd say let's validate the url and if it's valid let go, but I'm sure at this point. :-/

@voku
Copy link
Owner

voku commented Feb 11, 2023

Maybe related to issue #103

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants