-
Bug
-
Resolution: Fixed
-
High (View bug fix roadmap)
-
3.6.2
-
None
-
3.06
-
The 500 page in JIRA lists the request parameters, but does not HTML encode them. This can lead to cross site scripting.
The 500 page in JIRA lists the request parameters, but does not HTML encode them. This can lead to cross site scripting.
This was reported on Secunia and has since been resolved. This XSS iss ue is no longer an issue.
Cheers,
Nick