Details
Description
Steps to recreate:
1) go to (authenticate with admin/ofbiz):
https://localhost:8443/catalog/control/EditProductContent?productId=WG-1111
2) set the content of the field labeled "Large Image" to:
non_existent.foo" onerror="alert('Hi!');
3) visit the url:
https://localhost:8443/ecommerce/control/product?product_id=WG-1111
A popup message will appear with the "Hi!".
Thanks to Loris Nardo for the report.
Attachments
Issue Links
- is a child of
-
OFBIZ-1525 Issue to group security concerns
- Open
- is related to
-
OFBIZ-5254 Services allow arbitrary HTML for parameters with allow-html set to "safe"
- Closed