Details

    • Bug
    • Resolution: Fixed
    • Major
    • None
    • Professional Edition
    • Web Interface

    Description

      There is a potential for XSS if one decides to output the queryString returned by search input.
      Fixed by using the get_vars() function

      Attachments

        Activity

          [OBS-3713] Potential for XSS in menu search

          Yah, sure.. added in r11220.

          landy Mike Stupalov added a comment - Yah, sure.. added in r11220.

          People

            landy Mike Stupalov
            kentbjoh Kent Johannessen
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: