Pending

User tests: Successful: Unsuccessful:

avatar dcianciulli
dcianciulli
18 Jun 2018

There are some cases in which the link on the flag of the current language does not escape HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page url.

avatar dcianciulli dcianciulli - open - 18 Jun 2018
avatar dcianciulli dcianciulli - change - 18 Jun 2018
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 18 Jun 2018
Category Modules Front End
avatar Quy
Quy - comment - 18 Jun 2018
avatar peteruoi
peteruoi - comment - 18 Jun 2018

and plz close-delete this :)
https://developer.joomla.org/security.html

avatar franz-wohlkoenig franz-wohlkoenig - change - 18 Jun 2018
Status Pending Closed
Closed_Date 0000-00-00 00:00:00 2018-06-18 16:50:02
Closed_By franz-wohlkoenig
avatar joomla-cms-bot
joomla-cms-bot - comment - 18 Jun 2018
avatar joomla-cms-bot joomla-cms-bot - change - 18 Jun 2018
Closed_Date 2018-06-18 16:50:02 2018-06-18 16:50:04
Closed_By franz-wohlkoenig joomla-cms-bot
avatar joomla-cms-bot joomla-cms-bot - close - 18 Jun 2018
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 18 Jun 2018

closed as stated above, can't delete PR.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/20792.

Add a Comment

Login with GitHub to post a comment