Fixed
Pinned fields
Click on the next to a field label to start pinning.
Details
Assignee
SE SupportSE SupportReporter
Samuel KongSamuel Kong(Deactivated)Affects versions
Priority
Medium
Details
Details
Assignee
SE Support
SE SupportReporter
Samuel Kong
Samuel Kong(Deactivated)Affects versions
Priority
Zendesk Support
Zendesk Support
Zendesk Support
Created July 4, 2012 at 2:27 AM
Updated June 24, 2023 at 4:00 PM
Resolved July 4, 2012 at 2:30 AM
By carefully constructing a HTTP POST request, an attacker can execute any of the portal's web services. This vulnerability allows the attacker to circumvent both the permission system and the protection provided by the SecureFilter's portal properties:
xxx.servlet.hosts.allowed
xxx.servlet.https.required