Actions
Bug #9888
closedACME output sent to browser without encoding
Start date:
11/08/2019
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
Affected Version:
All
Affected Plus Version:
Affected Architecture:
All
Description
ACME issue/renew output is sent directly to the browser without encoding. In some cases, user input may be included in that output, leading to a potential XSS. Notably, the RootFolder
parameter for the webroot local folder
method is affected.
Actions