View Issue Details

IDProjectCategoryView StatusLast Update
5180Composr alpha bug reportsGeneral / Uncategorisedpublic2022-12-23 20:55
ReporterPDStig Assigned ToChris Graham  
PrioritynormalSeverityminor 
Status resolvedResolutionfixed 
Summary5180: side_news_archive Adding, then clearing, select param triggers XSS vulnerability
Descriptionside_news_archive block:

If select is left blank initially, it works correctly. However, if an item is added (select2) and then everything is removed, the block will then trigger XSS vulnerability. I'm not sure why as I'm not immediately spotting any difference in the parameters sent in the request.
TagsNo tags attached.
Attach Tags
Sponsorship open

Sponsor

Date Added Member Amount Sponsored

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2022-12-20 17:02 PDStig New Issue
2022-12-20 17:02 PDStig Status Not Assigned => Assigned
2022-12-20 17:02 PDStig Assigned To => Chris Graham
2022-12-23 20:55 Chris Graham Status Assigned => Resolved
2022-12-23 20:55 Chris Graham Resolution open => fixed
2023-02-26 18:29 Chris Graham Category General => General / Uncategorised