Project

General

Profile

Actions

Bug #16770

closed

Potential XSS in RSS Widget feed content post titles

Added by Jim Pingle 3 days ago. Updated 1 day ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
Dashboard
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.07
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

The RSS widget library does not encode post titles before display as it does with other content. As a consequence, if a feed configured in the RSS widget supplies content with a malicious payload in a post title, it could be delivered to the user's browser and executed.

A sample feed is attached.


Files

badfeed.xml (523 Bytes) badfeed.xml Jim Pingle, 03/31/2026 07:16 PM
Actions #1

Updated by Jim Pingle 3 days ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

Applied in changeset commit:9363ac5b8651a1c7a333180425ce7719070f95f9.

Actions #2

Updated by Jim Pingle 3 days ago

This is a basic feed that contains a post entry title which triggers the problem

Actions #3

Updated by Jim Pingle 1 day ago

  • Private changed from Yes to No
Actions #4

Updated by Jim Pingle 1 day ago

  • Status changed from Feedback to Resolved

Patch is available in the Recommended Patches section of the latest System Patches Package version.

Actions

Also available in: Atom PDF