-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Medium
-
Affects Version/s: 5.5
-
Component/s: None
-
6.5
This is from an external report. Creating a user with username:
"><img src=x onerror=prompt(1)>
and returning to the dashboard will demonstrate the script injection. This PoC will not work in Chrome/Chromium, but will in Firefox and other browsers that do not have such protective measures.
- mentioned in
-
Page Loading...