Details

      Description

      This potentially could happen

      1. Control Panel > Web Content > Manage > Feeds
      2. Add a feed
      3. Return to the view which list all the feeds
      4. Right click on the ID of the feed and copy the URL
      5. Past the URL into a new tab/window
      6. Change the value of "_15_feedId" parameter in the URL, for example:

      _15_feedId=123<script>alert(999)</script>

      And an alert windows will open.

      However, this currently does not happen because of other logic in the code which causes this line of code to not execute if the feedId is invalid.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                brian.wulbern Brian Wulbern
                Reporter:
                samuel.kong Samuel Kong
                Participants of an Issue:
                Recent user:
                Esther Sanz
              • Votes:
                0 Vote for this issue
                Watchers:
                0 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Days since last comment:
                  6 years, 19 weeks ago

                  Packages

                  Version Package
                  6.1.2 CE GA3
                  6.1.30 EE GA3
                  6.2.0 CE M6