Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
* Update CareersUI.php * SQL injection vulnerability fix in $entriesPerPage * Sanitize parameters against XSS attacks This commit fixes three XSS vulnerabilities. 1) 'indexFile' parameter /ajax.php?f=getPipelineJobOrder&joborderID=1&page=0&entriesPerPage=1&sortBy=dateCreatedInt&sortDirection=desc&indexFile=15)"></a><script>alert`xss`</script>&isPopup=0 2) 'entriesPerPage' parameter /ajax.php?f=getPipelineJobOrder&joborderID=2&page=0&entriesPerPage=15)"></a> <script>alert`xss`</script>&sortBy=dateCreatedInt&sortDirection=desc&indexFile=index.php&isPopup=0 3)'joborderID' parameter /ajax.php?f=getPipelineJobOrder&joborderID=1)"></a> <script>alert`xss`</script>&page=0&entriesPerPage=1&sortBy=dateCreatedInt&sortDirection=desc&indexFile=index.php&isPopup=0 * Fix for two XSS vulnerabilities in toolbar This commit will fix two XSS vulnerabilities in toolbar module functionality. 1) GET parameter 'callback'. /index.php?m=toolbar&callback=<script>alert`xss`</script>&a=authenticate 2) GET parameter 'email' /index.php?m=toolbar&callback=<script>alert`xss`</script>&a=checkEmailIsInSystem&email=<script>alert(document.domain)</script> * RCE vulnerability fix via insecure deserialization * Fix SQL injection vulnerability in Tag deletion * FIX SQL injection vulnerability in Imports module Co-authored-by: Mateo <[email protected]>
- Loading branch information