Details

      Description

      This potentially could happen

      1. Control Panel > Web Content > Manage > Feeds
      2. Add a feed
      3. Return to the view which list all the feeds
      4. Right click on the ID of the feed and copy the URL
      5. Past the URL into a new tab/window
      6. Change the value of "_15_feedId" parameter in the URL, for example:

      _15_feedId=123<script>alert(999)</script>

      And an alert windows will open.

      However, this currently does not happen because of other logic in the code which causes this line of code to not execute if the feedId is invalid.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              brian.wulbern Brian Wulbern
              Reporter:
              samuel.kong Samuel Kong
              Participants of an Issue:
              Recent user:
              Marta Elicegui
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Days since last comment:
                7 years, 20 weeks, 1 day ago

                  Packages

                  Version Package
                  6.1.2 CE GA3
                  6.1.30 EE GA3
                  6.2.0 CE M6