Vulnerabilities/

QooxDoo XSS in Callback Parameter

Severity:
Medium

Description

Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to inject arbitrary web script or HTML via the callback parameter.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
qooxdoo
Anything's wrong? Let us know Last updated on January 19, 2024

This issue is available in SmartScanner Professional

See Pricing