Details
-
Type:
Bug
-
Status: Closed
-
Priority:
Major
-
Resolution: Fixed
-
Affects Version/s: 3.0.RC1
-
Fix Version/s: 3.0, EE-1.8.2.GA_P04
-
Component/s: Framework
-
Labels:None
-
Environment:ICEfaces
-
Assignee Priority:P2
-
ICEsoft Forum Reference:
Description
If the ice.focus parameter is set to contain JavaScript, this may be executed on a subsequent page view.
As mentioned in the forum post, setting ice.focus:
ice.focus=form.starSearchClient');alert('Xss
will allow the JavaScript to be executed because the page contains:
Ice.focus.setFocus('form.startSearclClient');alert('Xss');
Activity
- All
- Comments
- History
- Activity
- Remote Attachments
- Subversion
Field | Original Value | New Value |
---|---|---|
Assignee | Ken Fyten [ ken.fyten ] |
Salesforce Case | [] | |
Fix Version/s | EE-1.8.2.GA_P04 [ 10280 ] |
Salesforce Case | [] | |
Assignee Priority | P2 | |
Assignee | Ken Fyten [ ken.fyten ] | Mircea Toma [ mircea.toma ] |
Status | Open [ 1 ] | Resolved [ 5 ] |
Resolution | Fixed [ 1 ] |
Status | Resolved [ 5 ] | Closed [ 6 ] |