You are here: Foswiki>Tasks Web>Item13833 (16 Nov 2015, GeorgeClark)Edit Attach

Item13833: Don't allow internal render markers to be passed in parameters, or rendered in topic text.

pencil
Priority: Security
Current State: Closed
Released In: 2.0.3
Target Release: patch
Applies To: Engine
Component:
Branches: master
Reported By: JozefMojzis
Waiting For:
Last Change By: GeorgeClark
Really weird.

http://foswiki/bin/oops?template=oopsgeneric&param1={%00script}%00alert(1){%00/script}%00;

-- JozefMojzis - 21 Oct 2015

 

ItemTemplate edit

Summary Don't allow internal render markers to be passed in parameters, or rendered in topic text.
ReportedBy JozefMojzis
Codebase 2.0.2, 2.0.1, 2.0.0, 1.1.9, trunk
SVN Range
AppliesTo Engine
Component
Priority Security
CurrentState Closed
WaitingFor
Checkins distro:63179b37e908
TargetRelease patch
ReleasedIn 2.0.3
CheckinsOnBranches master
trunkCheckins
masterCheckins distro:63179b37e908
ItemBranchCheckins
Release01x01Checkins
Topic revision: r3 - 16 Nov 2015, GeorgeClark
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License    Legal Imprint    Privacy Policy