Project

General

Profile

Actions

Bug #5095

closed
EA KD

XSS vulnerability - through url

Bug #5095: XSS vulnerability - through url

Added by Erhan Aydın about 10 years ago. Updated about 10 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Start date:
07/13/2016
Due date:
% Done:

0%

Estimated time:

Description

I can run scripts through url (tested on Mozilla Firefox):

https://www.webtoolkit.eu/wt/'\"--->

</style> </scRipt> <scRipt>

alert("boom")

</scRipt>

EA Updated by Erhan Aydın about 10 years ago Actions #1

Unescaped url (as pasted on address bar)

https://www.webtoolkit.eu/wt/'"--></style></scRipt><scRipt>alert("boom")</scRipt>

KD Updated by Koen Deforche about 10 years ago Actions #2

  • Status changed from New to Implemented @Emweb
  • Assignee set to Koen Deforche

Oops. This exists since version 3.2.0.

KD Updated by Koen Deforche about 10 years ago Actions #3

  • Status changed from Implemented @Emweb to Resolved

KD Updated by Koen Deforche about 10 years ago Actions #4

  • Status changed from Resolved to Closed
  • Target version set to 3.3.6
Actions

Also available in: PDF Atom