Uploaded image for project: 'Qt Project Website'
  1. Qt Project Website
  2. QTWEBSITE-113

XSS Vulnerability in Forums and Wiki

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • P0: Blocker
    • None
    • None
    • qt-project.org
    • None
    • Firefox

    Description

      The DevNet website is vulnerable to XSS attacks - as I can insert arbitrary tags using < and > - these are not escaped properly. Every "&" should be replaced by "&" in user input to fix this issue.

      Demonstration:

      http://developer.qt.nokia.com/forums/viewthread/2089/

      I'm setting priority to "Blocker", as this is a real serious issue.

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            mariusg mariusg (Inactive)
            thp Thomas Perl
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes