Project

General

Profile

Actions

Feature #607

closed
BN KD

Potential vulnerability with external references in HTML version

Feature #607: Potential vulnerability with external references in HTML version

Added by Boris N almost 16 years ago. Updated almost 15 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Start date:
11/17/2010
Due date:
% Done:

0%

Estimated time:

KD Updated by Koen Deforche almost 15 years ago Actions #2

  • Status changed from InProgress to Resolved
  • Target version set to 3.1.11

Hey,

We've implemented just this: to use a redirect-indirection in case the current URL contains the (current) session Id.
We still should add this to a few other places, like in the XSS filter and for image src URLs.

Regards,
koen

KD Updated by Koen Deforche almost 15 years ago Actions #3

  • Status changed from Resolved to Closed

Resolved in Wt 3.1.11

Actions

Also available in: PDF Atom