Skip to content
This repository has been archived by the owner on May 10, 2024. It is now read-only.

Improper localization sanitation #1

Open
cartpauj opened this issue Feb 22, 2011 · 0 comments
Open

Improper localization sanitation #1

cartpauj opened this issue Feb 22, 2011 · 0 comments

Comments

@cartpauj
Copy link

Failure to sanitize "location","First Name", "last Name", & "Bio" Fields, in Mingle "Account" page; allows an attacker, or any user to inject malicious HTML code and performing a presisitent XSS attack against other users. failure to sanitize the "subject" field in the "Messages" section allows an attacker to perform a stored XSS attack against any user of his choice.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant