Make WordPress Core

Opened 15 years ago

Closed 15 years ago

#18445 closed defect (bug) (fixed)

Unifiltered text can be inserted via Link Image To field when side-loading media

Reported by: DrewAPicture Owned by: azaozz
Priority: normal Milestone: 3.3
Component: Formatting Version: 3.2.1
Severity: normal Keywords: has-patch dev-feedback
Cc: Focuses:

Description

It looks like the replace methods were left out for f.url.value in wp-admin/includes/media.php. Thus, unfiltered text including complete javascript strings can be passed through the 'Link Image To' field when side-loading media via the 'From URL' tab. The unfiltered text is dropped untouched into the media's link tag and has potential to wreak havoc.

Reproduce:

In posting page-> Add media > Goto 'From URL' tab > Input a url to a valid remote image > Input special characters into the 'Link Image To' field > Insert into post.

Attachments (1)

18445.diff (737 bytes ) - added by DrewAPicture 15 years ago.
Remade patch root-relative at 18759

Download all attachments as: .zip

Change History (7)

#1 @DrewAPicture
15 years ago

  • Keywords has-patch added; needs-patch removed

#2 @SergeyBiryukov
15 years ago

  • Milestone Awaiting Review3.3

#3 @DrewAPicture
15 years ago

  • Component ValidationFormatting

Tested on trunk and inserted, side-loaded media URLs are now filtered as expected.

Last edited 15 years ago by DrewAPicture (previous) (diff)

#4 @DrewAPicture
15 years ago

  • Keywords dev-feedback added

@DrewAPicture
15 years ago

Remade patch root-relative at 18759

#5 @nacin
15 years ago

  • Owner set to azaozz
  • Status newassigned

#6 @azaozz
15 years ago

  • Resolutionfixed
  • Status assignedclosed

In [19275]:

Filter the link href when inserting external image in the editor, props DrewAPicture, fixes #18445

Note: See TracTickets for help on using tickets.