XSS vulnerability at "Edit Space Permissions"

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: High
    • 2.5.6, 2.6.0
    • Affects Version/s: 2.5.4
    • Component/s: None
    • Environment:

      Standalone

      Description:
      XSS vulnerability at "Edit Space Permissions" page

      Exploit:
      Write to the "Grant permission to" field: "<script>alert(document.cookie)</script>"

            Assignee:
            Unassigned
            Reporter:
            Gergely Hodicska
            Votes:
            1 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: