Skip to content

Javascript Injection possible #152

Open
@dommar04

Description

@dommar04

The image.php is vulnerable to Cross-Site Scripting
Example:
..../extensions/jit_image_manipulation/lib/image.php?param=%3Cscript%3Ealert%28%27XSS%27%29%3C/script%3E

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions