Actions
Bug #5095
closedXSS vulnerability - through url
Start date:
07/13/2016
Due date:
% Done:
0%
Estimated time:
Description
I can run scripts through url (tested on Mozilla Firefox):
https://www.webtoolkit.eu/wt/'\"--->
alert("boom")
Updated by Erhan Aydın over 8 years ago
Unescaped url (as pasted on address bar)
https://www.webtoolkit.eu/wt/'"--></style></scRipt><scRipt>alert("boom")</scRipt>
Updated by Koen Deforche over 8 years ago
- Status changed from New to Implemented @Emweb
- Assignee set to Koen Deforche
Oops. This exists since version 3.2.0.
Updated by Koen Deforche over 8 years ago
- Status changed from Implemented @Emweb to Resolved
Updated by Koen Deforche over 8 years ago
- Status changed from Resolved to Closed
- Target version set to 3.3.6
Actions