02-13-2013 05:06 PM
Vaadin 6.8.8 fixes a security issue discovered during an internal review.The activiti explorer, contained into activiti stack 5.10 and 5.11, uses…the vaadin-6.6.2.jar, (it was available at 15. juni 2011! )
Allowing unfiltered user input as the key in a map used for communication in a Vaadin UI component may enable a cross-site scripting (XSS) attack on a Vaadin application. Specifically, in certain cases it is possible to use a specially-crafted debug ID to inject arbitrary Javascript to be executed in an end user's browser. This requires specific actions both from the application developer and from the end user.
02-14-2013 01:37 AM
Tags
Find what you came for
We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.