Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

Overview and fix spots vulnurable for XSS attacks

#24

It was noted that there was an instance where an account was create an was able to inject a js text into the member.about field. Need to review such spots in the application where such an injection is possible and prevent it by means of Grails html escaping, etc.

Reported by dima767 (at gmail) · February 26th, 2009 @ 08:37 AM

State: resolved
Milestone: 1.2.1
Assigned to: dima767 (at gmail) dima767 (at gmail)

Activity

  1. dima767 (at gmail)
    dima767 (at gmail)
    • State changed from new to resolved

    May 24th, 2009 @ 05:40 PM

Please Sign in or create a free account to add a new ticket.

With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.