Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-15367

Fix XSS issue on document library gadget

    XMLWordPrintable

    Details

      Description

      After putting the following as a document title:

      "><iframe src="" onload="alert('I can see your cookies! ' + document.cookie)">
      

      Displaying the document in the document library gadget will popup the alert.

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: