Actions
Bug #23668
closedXSS in template analyzer
Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2010-10-04
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
4.5
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:
Description
Because of a missing htmlspecialchar() there is the possibiltiy of a XSS.
OTRS: 2010100110000031
Reporter: Susanne Moog
(issue imported from #M15887)
Files
Updated by Helmut Hummel about 14 years ago
PoC: Name a template "<script>alert(123)</script>" and switch to the Template analyzer
Actions