Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-11622

Unexpected input may cause xss risk in Taxonomy

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • App CMS 1.1.0
    • App CMS 1.1.2
    • App CMS
    • None

    Description

      when we use sling-cms demo ,we find it that input in [+taxonomy item]  may cause the XSS vulnerability。

      some one like eg.

      //代码占位符
      "><svg onload=alert('xss')></svg> 

       

      Attachments

        1. image-2022-10-18-16-09-21-603.png
          69 kB
          QSec-Team
        2. image-2022-10-18-16-09-45-520.png
          157 kB
          QSec-Team

        Activity

          People

            dklco Dan Klco
            QSecTeam QSec-Team
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: