Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
5.2 EE (5.2.4)
-
All
Description
A cross site scripting (XSS) vulnerability exist with the job title field in the Directory portlet. An attacker can potentially exploit this security vulnerability to insert malicious JavaScript into a page.
To address this issue, job titles are now escaped before they are displayed on a page.
Attachments
Issue Links
- is related to
-
LPS-3771 "Job Title" field in Summary portlet does not filter out HTML characters
- Closed