Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Security problem fixed#549

Merged
Danielss89 merged 1 commit into
ZF-Commons:masterfrom
mailjet:master
Jan 8, 2015
Merged

Security problem fixed#549
Danielss89 merged 1 commit into
ZF-Commons:masterfrom
mailjet:master

Conversation

@GyunerZeki

Copy link
Copy Markdown

Security problem fixed: XSS attack.

… parameter in login page (XSS).

If you open "/user/login?redirect=%22%3E%3Ca%20href=%22http://github.com%22%3EGitHub.com%3C/a%3E%3Cinpu%20type=%22hidden%22%20%22" you will see appended github link between "Not registered?" and "Sign up!"
Danielss89 added a commit that referenced this pull request Jan 8, 2015
Security problem fixed: possibility to insert HTML by URL as redirect pa...
@Danielss89 Danielss89 merged commit 2cc167a into ZF-Commons:master Jan 8, 2015
@Danielss89 Danielss89 changed the title Security problem fixed: possibility to insert HTML by URL as redirect pa... Security problem fixed Jan 8, 2015
@Danielss89 Danielss89 modified the milestones: 2.0.0, 1.2.2 Jan 8, 2015
@Danielss89

Copy link
Copy Markdown
Member

Thanks alot :)

@Maks3w

Maks3w commented Jan 12, 2015

Copy link
Copy Markdown
Contributor

For the record: The CVE assigned to this vulnerability is CVE-2015-1039

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants