Last modified: 2012-10-24 11:55:23 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T35963, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 33963 - Missing escaping in search-as-you-type suggestions of Monobook skin
Missing escaping in search-as-you-type suggestions of Monobook skin
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
JavaScript (Other open bugs)
unspecified
All All
: Low minor (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-01-26 12:05 UTC by Amalthea
Modified: 2012-10-24 11:55 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments
Suggestion popup. (4.48 KB, image/png)
2012-01-26 12:05 UTC, Amalthea
Details

Description Amalthea 2012-01-26 12:05:16 UTC
Created attachment 9909 [details]
Suggestion popup.

I have an alternate account named [User:Amalthea'"&lt] to test escaping issues in tools.
Using Monobook skin, when I type [User:Amalthea'] into the search input field, the search-as-you-type suggestion popup displays [User:Amalthea'"<].
I interpret this as my browser auto-correcting the broken entity [&lt] and displaying it as [<], which in turn means that the ampersand is not escaped properly when it's written into the suggestion popup.

Since page names are heavily sanitized I don't see a way that this can be exploited, but it should be fixed nonetheless.
Vector skin is behaving correctly.
Comment 1 Derk-Jan Hartman 2012-10-24 11:55:23 UTC
This seems fixed now...

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links