tomaioo's Description of Work
Summary
Security: Potential XSS via Unsanitized Board Data in settingsAbout.js
Problem
Severity: Medium | File: js/core/settingsAbout.js:L31
In settingsAbout.js, board data is retrieved via Espruino.Core.Env.getBoardData(), converted to strings, and then rendered into an HTML table using Espruino.Core.HTML.htmlTable(strData). This HTML is injected directly into the DOM using jQuery's .html() method. If the board data contains malicious HTML/JavaScript (e.g., through a manipulated firmware response), it could be executed in the context of the Web IDE, leading to XSS.
Solution
Ensure that Espruino.Core.HTML.htmlTable properly escapes all values being placed into HTML table cells. Use Espruino.Core.Utils.escapeHTML (which is used elsewhere in the same file) on the values before constructing the HTML table.
Changes
-
js/core/settingsAbout.js(modified)