[jira] [Created] (OFBIZ-11840) Reflected XSS in content component

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Created] (OFBIZ-11840) Reflected XSS in content component

Nicolas Malin (Jira)
Jacques Le Roux created OFBIZ-11840:
---------------------------------------

             Summary: Reflected XSS in content component
                 Key: OFBIZ-11840
                 URL: https://issues.apache.org/jira/browse/OFBIZ-11840
             Project: OFBiz
          Issue Type: Sub-task
          Components: content
    Affects Versions: 17.12.03
            Reporter: Jacques Le Roux


Harshit Shukla [mailto:[hidden email]] reported a  Reflected XSS  vulnerability in content component to the OFBiz security team, and we thank him for that.

I'll later quote here his email message when the vulnerability will be fixed. It's a post-auth vulnerability so we did not ask for a CVE.




--
This message was sent by Atlassian Jira
(v8.3.4#803005)