Cross-Site Scripting XSS (store javascript data without validation)
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Link issues together to show that they're related. Learn more.
Activity
- Jansen assigned to @johnLucious
assigned to @johnLucious
- Jansen mentioned in merge request !1 (closed)
mentioned in merge request !1 (closed)
- Jansen mentioned in merge request !2 (closed)
mentioned in merge request !2 (closed)
- Jansen mentioned in merge request !3 (merged)
mentioned in merge request !3 (merged)
- Alvin Limassa closed via merge request !3 (merged)
closed via merge request !3 (merged)
- Alvin Limassa mentioned in commit d5703941
mentioned in commit d5703941
- Author Owner
sistem akan menyimpan semua text yang diinput oleh user tanpa validasi atau escaping. Apabila user menggunakan tulisan javascript ( maka sistem akan menjalankan javascriptnya karena tidak di escape.
solve : sistem akan melakukan escape terhadap karakter < diganti dengan "".
Please register or sign in to reply