Skip to content
This repository has been archived by the owner on Apr 26, 2022. It is now read-only.

Security Fix for Cross-site Scripting (XSS) - huntr.dev #786

Open
wants to merge 8 commits into
base: 1.7-dev
Choose a base branch
from

Conversation

huntr-helper
Copy link

https://huntr.dev/users/b1nslashsh has fixed the Cross-site Scripting (XSS) vulnerability 馃敤. Think you could fix a vulnerability like this?

Get involved at https://huntr.dev/

Q | A
Version Affected | ALL
Bug Fix | YES
Original Pull Request | 418sec#1
Vulnerability README | https://github.com/418sec/huntr/blob/master/bounties/other/arastta/1/README.md

User Comments:

馃搳 Metadata *

Arastta is a Solid, Free, Open Source, Community Driven eCommerce this package is vulnerable to Reflected Cross-Site Scripting (XSS).

Bounty URL: https://www.huntr.dev/bounties/1-other-arastta

鈿欙笍 Description *

Fix fox xss in arastta

馃捇 Technical Description *

Actually 3 endpoints are vulnerable for xss
1) ./catalog/view/theme/second/template/error/not_found.tpl:10
2) ./catalog/view/theme/second/template/common/header.tpl:91
3)./catalog/view/theme/second/template/common/currency.tpl:25

Fixed all 馃憤

馃悰 Proof of Concept (PoC) *

pocxss

gdrive

馃敟 Proof of Fix (PoF) *

poc1
poc2
poc3
poc4

馃憤 User Acceptance Testing (UAT)

everything is working fine 馃憤
poc1

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants