Bug #8259
Range description is not encoded in firewall_schedule.php
100%
Description
On firewall_schedule.php the rangedescr for time ranges is not encoded before display. However, an invalid entry cannot be made using the GUI to take advantage of the issue.
Achieving an XSS requires manually modifying a backup to trigger the issue, and if someone can restore a manually modified backup, there are many worse things they could do. Thus it is not considered a viable threat.
Associated revisions
Encode rangedescr before display in firewall_schedules.php. Fixes #8259
(cherry picked from commit 2f7d3a1f3c9b00a815037e1f4b8a88c938a8f42d)
Encode rangedescr before display in firewall_schedules.php. Fixes #8259
(cherry picked from commit 2f7d3a1f3c9b00a815037e1f4b8a88c938a8f42d)
Encode rangedescr before display in firewall_schedules.php. Fixes #8259
(cherry picked from commit 2f7d3a1f3c9b00a815037e1f4b8a88c938a8f42d)
History
#1
Updated by Jim Pingle over 3 years ago
- Status changed from Confirmed to Feedback
- % Done changed from 0 to 100
Applied in changeset 2f7d3a1f3c9b00a815037e1f4b8a88c938a8f42d.
Encode rangedescr before display in firewall_schedules.php. Fixes #8259