Page MenuHomePhabricator

Reasonator XSS vulnerability
Closed, ResolvedPublicSecurity

Description

URL parameters like https://reasonator.toolforge.org/?find=%27%3C/input%3E%3Cscript%3Ealert(%27XSS%27)%3C/script%3E can be used to execute arbitrary JS.

Reporting on Phabricator per similar previous reports like T305764.

Details

Risk Rating
Medium
Author Affiliation
Wikimedia Communities

Related Objects

Event Timeline

@Magnus: Hi, where to report such issues?

sbassett triaged this task as Medium priority.Nov 27 2025, 4:18 PM
sbassett changed Author Affiliation from N/A to Wikimedia Communities.
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett changed the edit policy from "Custom Policy" to "All Users".
sbassett changed Risk Rating from N/A to Medium.