Skip to content

XSS vulnerability #16

@aidhog

Description

@aidhog

Raw user content is included into the results page, leading to potential issues with XSS for keyword queries like:

1"><script>alert(150)</script>

A quick solution (not requiring code changes) is to use the following guide: http://www.servletsuite.com/servlets/xssflt.htm

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions