Magnolia Sitedesigner

Cross Site Scripting Vulnerability (XSS) in Search

Details

  • Type: Bug Bug
  • Status: Resolved Resolved
  • Priority: Major Major
  • Resolution: Fixed
  • Affects Version/s: 1.1.4
  • Fix Version/s: 1.1.7
  • Component/s: None
  • Security Level: Public
  • Labels:
  • Description:

    Search for <script>alert('XSS')</script> and you see that the js code is executed. Please use the same fix as provided in the samples: MAGNOLIA-590

Issue Links

Activity

Hide
Tom Wespi added a comment - 15/Apr/08 9:11 AM

resolved in trunk

Show
Tom Wespi added a comment - 15/Apr/08 9:11 AM resolved in trunk

People

Dates

  • Created:
    14/Apr/08 1:12 PM
    Updated:
    17/Mar/09 7:48 PM
    Resolved:
    10/Jul/08 10:43 PM