xRM-Portals-Community-Edition icon indicating copy to clipboard operation
xRM-Portals-Community-Edition copied to clipboard

Cross-Site Scripting (XSS) on OOB Registration Page

Open mbtomlin opened this issue 5 years ago • 1 comments

I've been made aware of a Cross-Site Scripting (XSS) vulnerability on the oob registration button. The partial URL is Account/Login/Register?returnUrl=%2F

Has anyone else experienced this? If so, is it hard to fix or should I just roll my own registration page? Thanks.

mbtomlin avatar Jan 31 '20 21:01 mbtomlin

A fix contributed to this project would be ideal. If you'd like to discuss the specifics of the issue before making changes please write to me via the LinkedIn profile I have listed in my GitHub profile. This will help to avoid publically disclosing anything potentially sensitive prior to a fix being available.

amervitz avatar Jan 31 '20 23:01 amervitz