Cross Site Scripting XSS

Description

iDempiere has an XSS Stored vulnerability: it's possible to execute arbitrary javascript code.

Environment

None

Attachments

1

Activity

Show:

Carlos Ruiz June 5, 2019 at 10:11 AM

Thanks

Former user June 5, 2019 at 7:54 AM

I sent an email

Carlos Ruiz June 4, 2019 at 12:00 PM

Thanks , can you please ellaborate how to get that screenshot?

Which is the test case - some windows and fields are security sensitive and solution usually is to define it as System or Advanced to solve the issue.

If you think is better not to disclose this issue until solved, you can try following the procedure described here:
https://wiki.idempiere.org/en/How_to_report_a_vulnerability

Regards,

Carlos Ruiz

Fixed

Details

Assignee

Reporter

Labels

Fix versions

Priority

Created June 4, 2019 at 10:43 AM
Updated August 5, 2024 at 7:04 PM
Resolved June 9, 2021 at 1:32 PM