Uploaded image for project: 'Felix'
  1. Felix
  2. FELIX-6132

XSS possible in service console

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • webconsole-4.3.8
    • webconsole-4.3.12
    • Web Console
    • None

    Description

      Issue Summary : There is a XSS possible in system console.

      Steps to reproduce :

      1. Open a local instance
      2. Open the link http://localhost:4502/system/console/services?filter=%22onmouseover=%22alert(%27xss%27)%22 in Internet Explorer. A pop would come when you mouse over the filter input box.
      3. Chrome would auto flag XSS exploit and prevent page load

      Expected Behavior : The pop up should not come up.

      Attachments

        Issue Links

          Activity

            People

              karlpauls Karl Pauls
              ashokpanghal Ashok Kumar
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: