[SECURITY] XSS in header link of all content elements
The second typolink parameter, that is the target, can be abused to introduce XSS code into the generated link. Escaping the parameter with quoteJSvalue solves the problem. Change-Id: Ie91b022a2ffed039fb365e6b0be2ea39f7096514 Fixes: #31206 Releases: 6.2, 6.1, 6.0, 4.7, 4.5 Security-Commit: 484cf1aea8d3e66db547325fe4d843d50a668162 Security-Bulletin: TYPO3-CORE-SA-2013-004 Reviewed-on: https://review.typo3.org/26225 Reviewed-by: Oliver Hader Tested-by: Oliver Hader
parent
226d624a
Please register or sign in to comment