Actions
Bug #23550
closedSysext setup's user simulation is susceptible to XSS
Start date:
2010-09-17
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
4.2
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:
Description
The user simulation part of system extension (BE module) setup is vulnerable to Cross-Site-Scripting attacks. GET/POST parameter "simUser", which is supposed to be an integer value, is outputted as is.
OTRS-X-Reference: #2010083010000016
reported by: Daniel Sloof
(issue imported from #M15729)
Files
Actions