Descrição
Improper Neutralization of Input During Web Page Generation (-Cross-site Scripting-) vulnerability in woylie doggo allows Reflected XSS. Doggo.normalize_value/2 in lib/doggo.ex returned date field values wrapped in {:safe, ...}, the Phoenix.HTML marker meaning -already escaped, emit verbatim-, without escaping them, so the value reached the value attribute of the <input> rendered by the field component unchanged. Any application rendering <.field type=-date-> over user-controlled params is affected through the ordinary Phoenix form round-trip, where a failed validation re-renders the submitted value. The pattern kept exactly the first ten bytes and discarded shorter values, capping a payload at ten bytes: enough to terminate the attribute and open an element or attach a short event handler, not enough to place attacker-chosen script inline. Only type=-date- is affected. This issue affects doggo: from 0.1.0 before 0.14.8.
- Publicação
- 2026-08-27 20:18:27
- Versões afetadas
- >=0.1.0,<0.14.8
- Tipo
- Biblioteca
- Última alteração
- 2026-08-27 20:18:27
- Vetor
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X