Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-10054

Product content management screen doesn't validate trusted users' input

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: Trunk, Release Branch 16.11
    • Fix Version/s: 17.12.01, 16.11.06, 18.12.01
    • Component/s: product
    • Labels:
      None

      Description

      Steps to recreate:

      1) go to (authenticate with admin/ofbiz):
      https://localhost:8443/catalog/control/EditProductContent?productId=WG-1111

      2) set the content of the field labeled "Large Image" to:
      non_existent.foo" onerror="alert('Hi!');

      3) visit the url:
      https://localhost:8443/ecommerce/control/product?product_id=WG-1111

      A popup message will appear with the "Hi!".

      Thanks to Loris Nardo for the report.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                jleroux Jacques Le Roux
                Reporter:
                jacopoc Jacopo Cappellato
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: