Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS in pages title display #1311

Open
tablatronix opened this issue May 24, 2019 · 2 comments
Open

XSS in pages title display #1311

tablatronix opened this issue May 24, 2019 · 2 comments

Comments

@tablatronix
Copy link
Member

3.4
Screen Shot 2019-05-24 at 12 19 14 PM (2)

@tablatronix tablatronix added this to the 3.4.0 milestone May 24, 2019
@tablatronix tablatronix changed the title XSS in files filenames display XSS in pages title display May 24, 2019
@tablatronix
Copy link
Member Author

Apply Fix from hotfixes, should have been fixed there already

@tablatronix
Copy link
Member Author

tablatronix commented May 24, 2019

This is where xss from permalink gets output!
aha

Was saved in hotfixes, exploited in DEV, should not be injectable in DEV so not an issue

  • consider filtering output to prevent other injection vectors , xml etc.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant