in reply to clacke: exhausted pixie dream boy 🇸🇪🇭🇰💙💛

Nope, I'm wrong. Going to libranet.de/display/f1417ed3-2… or friendica.philipp.info/display… in incognito mode doesn't cause the alert.

So the display name is properly filtered in messages, it's just following or having the name in one's notifications that causes the unfiltered name to be output.

This entry was edited (2 years ago)
Unknown parent

mastodon - Link to source

Free Teks for sale, cheap

Oh, wow! I didn’t think any software would be *that* seriously broken. I’ll see about changing my profile tomorrow, but that means libranet has a major, major security flaw. I could tell it to load whatever JS code I wanted into your browser by setting my name appropriately.
in reply to clacke: exhausted pixie dream boy 🇸🇪🇭🇰💙💛

hm, @Steffen K9 🐰 which Friendica version do you use? I see @<script>alert("Tek");</script> posts with his "nickname" but no popup at all (the web-console doesn't show any errors too). I'm using the latest develop version of Friendica.
in reply to Free Teks for sale, cheap

@<script>alert("Tek");</script> @Steffen K9 🐰 I would like to do an anticipated release, alongside another fix that has yet to be merged, and we will do the regular announcement then, giving you the credit for the find.