Issue: |
|
---|---|
Date: |
|
Severity: | Low |
Requires Admin Access: | No |
Fix Version: | 3 |
Credit: | Elar Lang / elar -at - clarifiedsecurity.com |
Description: |
GET Parameter "url" is displayed back to output without proper escaping. |
Mitigation: |
Properly escape the url and hostId parameters |
References |
https://github.com/dotCMS/core/issues/6353 |