This repository was archived by the owner on Jul 15, 2024. It is now read-only.
HTML tags in entity names in the tree view are not sanitised
Package
QuickEntity Editor
Affected versions
<1.28.1
Patched versions
1.28.1
Impact
HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name.
Patches
Patched in version 1.28.1 of the application.
Workarounds
No possible workaround other than updating the application.