Actions
Bug #5201
closedStored XSS on authentication services
Start date:
09/24/2015
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:
Description
To reproduce the cross-site scripting:
1. Go to https://localhost:9090/system_authservers.php?act=new
- on field Descriptive name: "></option></select><img src=x onerror=alert(1)>
- fill other required fields
- save
2. Go to https://localhost:9090/diag_authentication.php
Alert appears
Files
Actions