in media manager try to rename a file to
`"'><img src=xxx:x \x00onerror=javascript:alert(1)> </style  ><script   :-(>/**/alert(document.location)/**/</script   :-(
Error message from the ajax is captured and displayed
Just "Internal Server Error" is displayed in the error message when there is a more descriptive message in the JSON response
Joomla! 4.0.0-alpha3 Alpha [ Amani ] 12-May-2018 15:23 GMT
Labels |
Added:
?
|
Category | ⇒ | com_media UI/UX |
Status | New | ⇒ | Discussion |
Labels |
Added:
?
|
Labels |
Removed:
?
|
Labels |
Added:
J4 Issue
|
Would end up then like
with the code https://github.com/joomla-projects/media-manager-improvement/compare/rename?expand=1. But honestly I'm not really happy with it at all as we can't detect if there is a server error or a permission exception when a file can't be moved.
Status | Discussion | ⇒ | Closed |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2019-02-10 21:34:03 |
Closed_By | ⇒ | PhilETaylor |
Labels |
Added:
?
|
Labels |
Removed:
?
|
@joomla/security Might need a review of this....