View Password - Less critical - Cross Site Scripting - SA-CONTRIB-2024-026

Джерело:
Security advisories for contributed projects

Дата публікації:
31/07/2024 18:59

Постійна адреса новини:
http://www.vsinovyny.com/11177469

View Password - Less critical - Cross Site Scripting - SA-CONTRIB-2024-026

 

31/07/2024 18:59 // Security advisories for contributed projects

Project: 
Date: 
2024-July-31
Security risk: 
Vulnerability: 
Cross Site Scripting
Affected versions: 
<6.0.4
Description: 

The View Password module enables you to add a help icon button next to the password input field to toggle the password visibility. The administrative user is allowed to add classes to this icon for styling purposes.

The module doesn't validate the content of classes. A malicious user with access to the View Password Settings Form could add malicious code in the classes field.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer view password".

Solution: 

Install the latest version:

Reported By: 
Fixed By: 
Coordinated By: 

 

» Читати повністю

 

« Наступна новина з архіву
10 найкращих ігор з повною свободою дій, які скрасять очікування GTA 6
  Попередня новина з архіву
Україна виступила у фіналі веслувального слалому на Олімпіаді-2024. Яке місце
»

 

 
© 2026 www.vsinovyny.com