View Issue Details

IDProjectCategoryView StatusLast Update
0005236Composr alpha bug reports[All Projects] General / Uncategorisedpublic2023-01-09 16:52
ReporterPatrick SchmalstigAssigned ToChris Graham 
SeverityMinor-bug 
Status assignedResolutionopen 
Summary0005236: multi_content: XSS vulnerability when comcode_page is selected along with an undetermined other content
DescriptionSometimes block_main_multi_content will throw XSS vulnerability. This happens when comcode_page content type is selected and some other content types are also selected which I cannot seem to determine.

Does not happen if comcode_page is not chosen or if comcode_page is the only item chosen. Also does not seem to happen if comcode_page and only one other content_type is chosen. Also works if every content type is selected. Very annoying / weird combinations trigger XSS.
TagsNo tags attached.
Sponsorship open

Activities

Patrick Schmalstig

2023-01-09 16:52

administrator   ~0007862

Seems like a cache issue. When it happens, clearing the cache fixes it.

Issue History

Date Modified Username Field Change
2023-01-07 01:58 Patrick Schmalstig New Issue
2023-01-07 01:58 Patrick Schmalstig Status non-assigned => assigned
2023-01-07 01:58 Patrick Schmalstig Assigned To => Chris Graham
2023-01-07 01:59 Patrick Schmalstig Description Updated View Revisions
2023-01-07 02:00 Patrick Schmalstig Description Updated View Revisions
2023-01-09 16:52 Patrick Schmalstig Note Added: 0007862
2023-02-26 18:29 Chris Graham Category General => General / Uncategorised