Joris Lambrechts

Results 1 issues of Joris Lambrechts

We recently noticed a xss attempt using the following url: `solr-search?q=&facet=itemtype:%22New%3Cimg%20src=x%20onerror=alert(document.domain)%3E%22` They used inline javascript in a img-tag in the facet part of the query url. These facet values aren't...