I was just having a look at the marketplace api, when I saw the following under the URL https://marketplace.atlassian.com/rest/2/vendors/1211323 :
{ "_links": { "self": { "href": "/rest/2/vendors/1211323" }, "alternate": { "href": "/vendors/1211323", "type": "text/html" }, "addons": { "href": "/rest/2/addons/vendor/1211323" }, "contacts": { "href": "/rest/2/vendors/1211323/contacts" } }, "_embedded": {}, "name": "'\"><svg/onload=prompt(0);>", "description": "'\"><svg/onload=prompt(0);>", "address": { "line1": "'\"><svg/onload=prompt(0);>", "line2": "'\"><svg/onload=prompt(0);>", "city": "'\"><svg/onload=prompt(0);>", "state": "'\"><svg/onload=prompt(0);>", "postCode": "'\"><svg/onload=prompt(0);>", "country": "Azerbaijan" }, "email": "x@yahoo.com", "phone": "'\"><svg/onload=prompt(0);>", "vendorLinks": { "homePage": "https://marketplace.atlassian.com/manage/vendor/create", "sla": "https://marketplace.atlassian.com/manage/vendor/create" }, "supportDetails": { "supportOrg": { "name": "'\"><svg/onload=prompt(0);>", "supportUrl": "https://marketplace.atlassian.com/manage/vendors/1211323/details#supportUrl" } }, "otherContactDetails": "'\"><svg/onload=prompt(0);>" }
The <svg ...> tags seems very strange. Don't know if this is a bug or not?
regards,
Wim
Not a bug, looks like just someone messing around testing the API. I presume the pseudo-tag strings were meant to test whether HTML escaping behaves correctly. We'll remove this listing and will ask the user not to do this.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.