Skip to content
This repository has been archived by the owner on Apr 30, 2021. It is now read-only.

Fixed an XSS vulnerability #6

Merged
merged 1 commit into from
Sep 29, 2020
Merged

Conversation

lacaulac
Copy link
Contributor

HTML code could be displayed by passing it as an error GET parameter. This can lead to Javascript execution, which in turn can lead to user impersonation.

HTML code could be displayed by passing it as an `error` GET parameter. This can lead to Javascript execution, which in turn can lead to user impersonation.
@Chris92de Chris92de merged commit 9a45087 into Chris92de:master Sep 29, 2020
lacaulac added a commit to lacaulac/AdminServ that referenced this pull request Sep 29, 2020
I missed this one when looking into the other vulnerability fixed with Chris92de#6
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants