Details

    Description

      This potentially could happen

      1. Control Panel > Web Content > Manage > Feeds
      2. Add a feed
      3. Return to the view which list all the feeds
      4. Right click on the ID of the feed and copy the URL
      5. Past the URL into a new tab/window
      6. Change the value of "_15_feedId" parameter in the URL, for example:

      _15_feedId=123<script>alert(999)</script>

      And an alert windows will open.

      However, this currently does not happen because of other logic in the code which causes this line of code to not execute if the feedId is invalid.

      Attachments

        Issue Links

          Activity

            People

              brian.wulbern Brian Wulbern
              samuel.kong Samuel Kong
              Austin Chiang Austin Chiang
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:
                9 years, 43 weeks, 1 day ago

                Packages

                  Version Package
                  6.1.2 CE GA3
                  6.1.30 EE GA3
                  6.2.0 CE M6