Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
XSS Vulnerability IW 15.2.23
#1
Hello.  

I have recently had a security scan done on a site I am working on and it is reported that JavaScript can be injected into the page (XSS) as shown below.  I am using IW 15.2.23 at the moment and wonder if there is something I can do to prevent it.

URLhttps://dummydomain.com/

Method: POST

Parameter: IW_SessionID_

Attack: '"<scrIpt>alert(1);</scRipt>

Evidence: '"<scrIpt>alert(1);</scRipt>



URL: https://dummydomain.com/$/callback?callback=IWEDIT1.DoOnAsyncChange

Method: POST

Parameter: IW_SessionID_

Attack: '"<scrIpt>alert(1);</scRipt>
Evidence: '"<scrIpt>alert(1);</scRipt>


Not entirely sure how to test for this on the local SA application so that I can check it has been fixed.

Any advise would be appreciated. XSS is not something I have much experience with.

David.
Reply


Messages In This Thread
XSS Vulnerability IW 15.2.23 - by davidmcevoy@outlook.com - 09-05-2024, 10:50 AM
RE: XSS Vulnerability IW 15.2.23 - by joelcc - 09-10-2024, 04:13 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)