ispcfg3
ispcfg3 copied to clipboard
Cross site scripting attack
Client can easily change the html code from inspect element remove the disable tag from add website button and create unlimited websites. Can change the id on the delete website form button and destroy an other users website. On your php code you must validate that the current user can make changes only on own websites,databases,dns,mails,etc...
Is this fixed?
Wondering the same thing. Don't see anything in the commit history to suggest it was fixed.