Self-xss ?)
XSS caused by lax filtering of AD emails
I have a good habit of using nicknames. I like to use <script> alert ('test') </script>. Maybe it will pop up one day. So one day I opened my QQ mailbox and saw an advertisement email reminding me that my friend's birthday was approaching.
Just click it.
I didn't respond at first, but then I remembered it was a problem with my mailbox nickname.
Although it seems that you can only play on your own, it is also a storage-type cross-site, basically no harm (of course, it may be that I did not find a more dangerous way to use it ), but I still want to fix it. Thank you!
Proof of vulnerability:
You only need to set the mailbox nickname to something like <script> alert ('test') </script>. Then, when a friend sends an email to himself on his birthday, it can play.
Solution:
Filter user input