Skip to content

profile stored XSS vulnerability #448

@tcnichol

Description

@tcnichol

Stored XSS: Many of the profile fields (such as first and last name) are
vulnerable to XSS. When visiting the profile page, the script stored in those
fields will execute. e.g https://cpmr.tacc.utexas.edu/profile/viewProfile/
66101cce428a36d45381c305

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions