Uploaded image for project: 'Magnolia Soft Locking Module'
  1. Magnolia Soft Locking Module
  2. MGNLSLOCK-21

Parameters allow JavaScript, which is returned and executed on client - XSS Vulnerability

XMLWordPrintable

      The Soft-Locking Module will accept a parameter containing JavaScript, and return it to the client, where the JavaScript then gets executed.

      This will allow XSS attacks in the form of links sent to Editors.

      Example:

      http://demo.magnolia-cms.com/demo-project.html?isSoftLockingAjaxRequest=true&op=%3CSCRIPT%3Ealert%28%2220110927%20-%20XSS%20via%20URL%20Ajax%22%29;%3C/SCRIPT%3E

        Acceptance criteria

              fgrilli Federico Grilli
              runger Richard Unger
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Bug DoR
                  Task DoD