Uploaded image for project: 'VCL'
  1. VCL
  2. VCL-486

Measures against cross site scripting on the Login form

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.2
    • 2.2.2, 2.3
    • web gui (frontend)

    Description

      The Userid entry on the Login form is vulnerable to cross site scripting. We have prevented exploitation by sanitizing the Userid.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            operation-v@ml.itg.hitachi.co.jp Toru Yokoyama
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment