in reply to clacke: exhausted pixie dream boy 🇸🇪🇭🇰💙💛

Nope, I'm wrong. Going to libranet.de/display/f1417ed3-2… or friendica.philipp.info/display… in incognito mode doesn't cause the alert.

So the display name is properly filtered in messages, it's just following or having the name in one's notifications that causes the unfiltered name to be output.

This entry was edited (1 year ago)
Unknown parent

mastodon - Link to source

Teknique is my middle name

Oh, wow! I didn’t think any software would be *that* seriously broken. I’ll see about changing my profile tomorrow, but that means libranet has a major, major security flaw. I could tell it to load whatever JS code I wanted into your browser by setting my name appropriately.
in reply to clacke: exhausted pixie dream boy 🇸🇪🇭🇰💙💛

hm, @Steffen K9 🐰 which Friendica version do you use? I see @<script>alert("Tek");</script> posts with his "nickname" but no popup at all (the web-console doesn't show any errors too). I'm using the latest develop version of Friendica.
in reply to Teknique is my middle name

@<script>alert("Tek");</script> @Steffen K9 🐰 I would like to do an anticipated release, alongside another fix that has yet to be merged, and we will do the regular announcement then, giving you the credit for the find.