Mercurial > kallithea
comparison docs/installation_iis.rst @ 7547:a8d873e9cab0
compare: prevent XSS due to unescaped branch/tag/bookmark names
In the revision selection dropdown of the 'Compare' functionality, the
branch/tag/bookmark names were not correctly escaped.
This means that if an attacker is able to push a branch/tag/bookmark
containing HTML/JavaScript in its name, then that code would be evaluated.
This is a cross-site scripting (XSS) vulnerability.
Fix the problem by correctly escaping the branch/tag/bookmarks.
author | Thomas De Schampheleire <thomas.de_schampheleire@nokia.com> |
---|---|
date | Tue, 26 Feb 2019 21:27:42 +0100 |
parents | 9de61c5b8694 |
children | 19af3fef3b34 |
comparison
equal
deleted
inserted
replaced
7546:391fde4cbf12 | 7547:a8d873e9cab0 |
---|