Skip to content
This repository has been archived by the owner on Jul 29, 2023. It is now read-only.

Cross site scripting attack #39

Open
k4mikazi666 opened this issue Apr 29, 2019 · 2 comments
Open

Cross site scripting attack #39

k4mikazi666 opened this issue Apr 29, 2019 · 2 comments
Assignees

Comments

@k4mikazi666
Copy link

Client can easily change the html code from inspect element remove the disable tag from add website button and create unlimited websites. Can change the id on the delete website form button and destroy an other users website. On your php code you must validate that the current user can make changes only on own websites,databases,dns,mails,etc...

@cwispy cwispy self-assigned this Mar 5, 2020
@mikefnasr
Copy link

Is this fixed?

@danny6167
Copy link

Wondering the same thing. Don't see anything in the commit history to suggest it was fixed.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants