[ https://issues.apache.org/jira/browse/OFBIZ-260?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Jacques Le Roux updated OFBIZ-260: ---------------------------------- Issue Type: Sub-task (was: Bug) Parent: OFBIZ-1525 > Cross Site Scripting Vulnerability (XSS) > ---------------------------------------- > > Key: OFBIZ-260 > URL: https://issues.apache.org/jira/browse/OFBIZ-260 > Project: OFBiz > Issue Type: Sub-task > Components: specialpurpose/ecommerce > Affects Versions: Trunk > Reporter: Marco Risaliti > Assignee: David E. Jones > Fix For: Trunk > > > It's a copy of http://jira.undersunconsulting.com/browse/OFBIZ-559 from > Olivier Lietz. > =========================================================== > *Very* simple test: > /ecommerce/control/keywordsearch?SEARCH_STRING=<script>alert("XSS");</script> > Other components beside ecommerce are also affected. > -- This message was sent by Atlassian JIRA (v6.3.4#6332)