Skip to content

[Security] HTML injection via unsanitized thumbnailUrl in GoPro alert dialog #3376

Description

@numbers-official

Summary

The GoPro media list component directly interpolates user-controlled thumbnailUrl data into an HTML string passed to Ionic's alertCtrl.create() message parameter, enabling HTML injection if an attacker can control the thumbnail URL value.

Location

File: src/app/features/settings/go-pro/go-pro-media-list-on-camera/go-pro-media-list-on-camera.component.ts
Lines: 164-178

async fileWasUploadedBefore(fileToUpload: GoProFile | undefined) {
  if (!fileToUpload) return;

  const alert = await this.alertCtrl.create({
    cssClass: 'go-pro-alert-message-with',
    header: 'File Upload Error!',
    subHeader: 'File Previously Uploaded.',
    message: `<img src="${fileToUpload.thumbnailUrl}"  loading="lazy" decoding="async">`,
    buttons: ['OK'],
  });

  await alert.present();
}

Impact

Ionic's AlertController renders the message property as raw HTML via innerHTML. If an attacker can influence the fileToUpload.thumbnailUrl value (e.g., via a compromised or spoofed GoPro camera API response, or man-in-the-middle on local network), they could inject arbitrary HTML:

" onerror="maliciousCode()" alt="

This would result in:

<img src="" onerror="maliciousCode()" alt=""  loading="lazy" decoding="async">

Risk Level: Medium-High — requires attacker control over GoPro camera API responses or local network MITM, but exploitable in local/WiFi environments where GoPro communication occurs.

Suggested Fix

Sanitize the URL before interpolation, or avoid inline HTML entirely:

async fileWasUploadedBefore(fileToUpload: GoProFile | undefined) {
  if (!fileToUpload) return;

  // Option 1: Sanitize the URL
  const sanitizedUrl = encodeURI(fileToUpload.thumbnailUrl || '');

  const alert = await this.alertCtrl.create({
    cssClass: 'go-pro-alert-message-with',
    header: 'File Upload Error!',
    subHeader: 'File Previously Uploaded.',
    message: 'This file has been previously uploaded.',
    buttons: ['OK'],
  });

  await alert.present();
}

Alternatively, if the thumbnail must be shown, use Angular's DomSanitizer to validate the URL or display the image through a separate modal component with proper Angular template binding instead of raw HTML interpolation.

Generated by Health Monitor with Omni

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityPull requests that address a security vulnerability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions