Title: XSS on 404 page
Type: security Severity: major
Components: Web interface Versions: 1.6
Status: fixed Resolution: fixed
Dependencies: Superseder:
Assigned To: rouilj Nosy List: mdk, rouilj
Priority: high Keywords: patch

Created on 2019-03-22 18:46 by mdk, last changed 2019-03-22 22:28 by rouilj.

msg6417 Author: [hidden] (mdk) Date: 2019-03-22 18:46

An XSS has been found and reported I'm cross posting it
here so you can fix it too :)
msg6418 Author: [hidden] (rouilj) Date: 2019-03-22 22:28
applied patch from github. encoding the client.path with cgi.encode

Applied on trunk and maint-1.6 braches.

Thanks for opening the ticket here mdk.
