Beschreibung
Improper Neutralization of Input During Web Page Generation (-Cross-site Scripting-) vulnerability in woylie doggo allows Reflected XSS. Doggo.normalize_value/2 in lib/doggo.ex returned date field values wrapped in {:safe, ...}, the Phoenix.HTML marker meaning -already escaped, emit verbatim-, without escaping them, so the value reached the value attribute of the <input> rendered by the field component unchanged. Any application rendering <.field type=-date-> over user-controlled params is affected through the ordinary Phoenix form round-trip, where a failed validation re-renders the submitted value. The pattern kept exactly the first ten bytes and discarded shorter values, capping a payload at ten bytes: enough to terminate the attribute and open an element or attach a short event handler, not enough to place attacker-chosen script inline. Only type=-date- is affected. This issue affects doggo: from 0.1.0 before 0.14.8.
- Veröffentlicht
- 2026-08-27 20:18:27
- Betroffene Versionen
- >=0.1.0,<0.14.8
- Typ
- Bibliothek
- Zuletzt geändert
- 2026-08-28 16:18:20
- Vektor
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X