Summary
The GoPro media list component directly interpolates user-controlled thumbnailUrl data into an HTML string passed to Ionic's alertCtrl.create() message parameter, enabling HTML injection if an attacker can control the thumbnail URL value.
Location
File: src/app/features/settings/go-pro/go-pro-media-list-on-camera/go-pro-media-list-on-camera.component.ts
Lines: 164-178
async fileWasUploadedBefore(fileToUpload: GoProFile | undefined) {
if (!fileToUpload) return;
const alert = await this.alertCtrl.create({
cssClass: 'go-pro-alert-message-with',
header: 'File Upload Error!',
subHeader: 'File Previously Uploaded.',
message: `<img src="${fileToUpload.thumbnailUrl}" loading="lazy" decoding="async">`,
buttons: ['OK'],
});
await alert.present();
}
Impact
Ionic's AlertController renders the message property as raw HTML via innerHTML. If an attacker can influence the fileToUpload.thumbnailUrl value (e.g., via a compromised or spoofed GoPro camera API response, or man-in-the-middle on local network), they could inject arbitrary HTML:
" onerror="maliciousCode()" alt="
This would result in:
<img src="" onerror="maliciousCode()" alt="" loading="lazy" decoding="async">
Risk Level: Medium-High — requires attacker control over GoPro camera API responses or local network MITM, but exploitable in local/WiFi environments where GoPro communication occurs.
Suggested Fix
Sanitize the URL before interpolation, or avoid inline HTML entirely:
async fileWasUploadedBefore(fileToUpload: GoProFile | undefined) {
if (!fileToUpload) return;
// Option 1: Sanitize the URL
const sanitizedUrl = encodeURI(fileToUpload.thumbnailUrl || '');
const alert = await this.alertCtrl.create({
cssClass: 'go-pro-alert-message-with',
header: 'File Upload Error!',
subHeader: 'File Previously Uploaded.',
message: 'This file has been previously uploaded.',
buttons: ['OK'],
});
await alert.present();
}
Alternatively, if the thumbnail must be shown, use Angular's DomSanitizer to validate the URL or display the image through a separate modal component with proper Angular template binding instead of raw HTML interpolation.
Generated by Health Monitor with Omni
Summary
The GoPro media list component directly interpolates user-controlled
thumbnailUrldata into an HTML string passed to Ionic'salertCtrl.create()message parameter, enabling HTML injection if an attacker can control the thumbnail URL value.Location
File:
src/app/features/settings/go-pro/go-pro-media-list-on-camera/go-pro-media-list-on-camera.component.tsLines: 164-178
Impact
Ionic's
AlertControllerrenders themessageproperty as raw HTML viainnerHTML. If an attacker can influence thefileToUpload.thumbnailUrlvalue (e.g., via a compromised or spoofed GoPro camera API response, or man-in-the-middle on local network), they could inject arbitrary HTML:This would result in:
Risk Level: Medium-High — requires attacker control over GoPro camera API responses or local network MITM, but exploitable in local/WiFi environments where GoPro communication occurs.
Suggested Fix
Sanitize the URL before interpolation, or avoid inline HTML entirely:
Alternatively, if the thumbnail must be shown, use Angular's
DomSanitizerto validate the URL or display the image through a separate modal component with proper Angular template binding instead of raw HTML interpolation.Generated by Health Monitor with Omni