-
-
Notifications
You must be signed in to change notification settings - Fork 775
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
XSS from GitHub <script>alert(1)</script> #5656
Comments
Issue Status: 1. Open 2. Started 3. Submitted 4. Done This issue now has a funding of 0.4 ETH (50.67 USD @ $126.68/ETH) attached to it.
|
⚡️ A tip worth 0.20000 ETH (25.34 USD @ $126.68/ETH) has been granted to @marsrobertson for this issue from @owocki. ⚡️ Nice work @marsrobertson! Your tip has automatically been deposited in the ETH address we have on file.
|
|
Issue Status: 1. Open 2. Started 3. Submitted 4. Done Work has been started. These users each claimed they can complete the work by 1 week, 5 days from now. 1) mul53 has been approved to start work. Hi, i have looked around and found one of the areas not been escaped is the Submit A Plan field. I will look around more and make fixes if approved. Learn more on the Gitcoin Issue Details page. |
That is very kind, didn't expect a tip! (yeah, it took only HALF YEAR to report as a bug) |
@owocki, i want to create a bounty in the test environment. It says |
I think it caused issues with other parts of the page, @thelostone-mc @danlipert you guys remember why we disabled that? |
@kuhnchris @mul53 yeah, it was causing issues in quite a few places so we ended up disabling it |
@mul53 Hello from Gitcoin Core - are you still working on this issue? Please submit a WIP PR or comment back within the next 3 days or you will be removed from this ticket and it will be returned to an ‘Open’ status. Please let us know if you have questions!
Funders only: Snooze warnings for 1 day | 3 days | 5 days | 10 days | 100 days |
|
Issue Status: 1. Open 2. Started 3. Submitted 4. Done Work for 0.4 ETH (51.69 USD @ $129.23/ETH) has been submitted by: @owocki please take a look at the submitted work:
|
Hey what’s the status on this, I’m kinda locked up on the number of bounties I can pick up. |
Issue Status: 1. Open 2. Started 3. Submitted 4. Done The funding of 0.4 ETH (56.22 USD @ $140.54/ETH) attached to this issue has been approved & issued to @mul53. Additional Tips for this Bounty:
|
https://gitcoin.co/issue/kleros/hackathon/1/2824
It fetches content from GitHub issue, that has some XSS...
It only took me half a year to report.
The text was updated successfully, but these errors were encountered: