Project

General

Profile

Actions

Bug #10355

closed

diag_ping.php: Potential XSS via Hostname parameter

Added by Jim Pingle about 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Diagnostics
Target version:
Start date:
03/18/2020
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:

Description

On diag_ping.php, the hostname isn't fully validated and the output is not encoded, leading to a potential XSS.

Using an input such as the following example demonstrates the problem:

127.0.0.1 <img src='' onerror='alert()'>
Actions

Also available in: Atom PDF