Details

    • Story Points:
      2
    • Fix Priority:
      4
    • Similar Issues:
      Show 5 results 

      Description

      1. add asset publisher to a page
      2. go to Configuration -> Setup
      3. go to Archive/Restore Setup
      4. save your setup as <script>alert("www.eo.pl");</script
        Effect: almost immediately you will see javascript error because HTML in that name was not escaped. This is security bug.

        Activity

        Hide
        Paul Piao (Inactive) added a comment -

        Hi Szymon,
        Thank you for your report. I was able to reproduce this issue in 6.1.0 B3. I have also tested this issue on trunk revision 93508 and I was also reproduce. I will update the this ticket to reflect the issue.

        Show
        Paul Piao (Inactive) added a comment - Hi Szymon, Thank you for your report. I was able to reproduce this issue in 6.1.0 B3. I have also tested this issue on trunk revision 93508 and I was also reproduce. I will update the this ticket to reflect the issue.
        Hide
        Kiyoshi Lee added a comment -

        PASSED Manual Testing following the steps in the description.

        Reproduced on:
        Tomcat 7.0 + MySQL 5. 6.2.x Revision: 95520.

        Fixed on:
        Tomcat 7.0 + MySQL 5. 6.1.x Revision: 96736.
        Tomcat 7.0 + MySQL 5. 6.2.x Revision: 96736.

        Javascript error is no longer present.

        Show
        Kiyoshi Lee added a comment - PASSED Manual Testing following the steps in the description. Reproduced on: Tomcat 7.0 + MySQL 5. 6.2.x Revision: 95520. Fixed on: Tomcat 7.0 + MySQL 5. 6.1.x Revision: 96736. Tomcat 7.0 + MySQL 5. 6.2.x Revision: 96736. Javascript error is no longer present.
        Hide
        Edward Gonzales added a comment -

        Hello everyone! We are in the process of removing component "Portlet" from LPS. Please make the necessary adjustments to affected filters. Thanks!

        Show
        Edward Gonzales added a comment - Hello everyone! We are in the process of removing component "Portlet" from LPS. Please make the necessary adjustments to affected filters. Thanks!

          People

          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:
              Days since last comment:
              2 years, 11 weeks, 2 days ago

              Development

                Structure Helper Panel