Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[vulnerability][demo] no-hook-authorization parameter is missing in sub documents #245

Closed
t2ym opened this issue Apr 19, 2018 · 0 comments
Closed

Comments

@t2ym
Copy link
Owner

t2ym commented Apr 19, 2018

[vulnerability][demo] no-hook-authorization parameter is missing in sub documents

Root Cause

  • no-hook-authorization search parameter is missing in demo/sub-document|sub-sub-document|empty-document.html

Vulnarability

  • <script no-hook>/* unauthorized no hook inline script */</script> is executed without authorization
  • <script src="unauthorized-no-hook-script.js?no-hook=true"></script> is executed without authorization
@t2ym t2ym closed this as completed in 7f734a2 Apr 19, 2018
t2ym added a commit that referenced this issue Apr 19, 2018
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

1 participant