cancel
Showing results for 
Search instead for 
Did you mean: 

Cross Site Scripting Attacks

ahamed_rasmi
Champ in-the-making
Champ in-the-making
Hi,

We need to get approval for Security team before application be rolled out.

When we sought approval, they concluded Alfresco Share is prone to Cross Site Scripting Attacks…

I need help to overcome this issue and get the things going..

Ver: Alfresco 3.3
Browser: IE7..

Thanks in Advance
5 REPLIES 5

mikeh
Star Contributor
Star Contributor
If you've found a reproducible bug, the correct place to log it is JIRA (see the link in my signature below).

Thanks,
Mike

ahamed_rasmi
Champ in-the-making
Champ in-the-making
I posted in JIRA.. It was accepted.. But not accessible..

May i know the reason mike..? ALF-2623 is the code..

Regards,

Ahamed Rasmi

mikeh
Star Contributor
Star Contributor
Generally, if an XSS or similar security issue has been identified and is reproducible, we set the JIRA issue to be accessible by Alfresco staff only - that way it's not "Googleable".

Thanks,
Mike

ahamed_rasmi
Champ in-the-making
Champ in-the-making
Ok.. then how would i know about the status… and possible solutions..

Do you think UrlRewrite way with regex would solve this issue?

Regards

Ahamed

ahamed_rasmi
Champ in-the-making
Champ in-the-making
I have fixed the issue.. now share site is safe..

Added a Filter..

In filter replaced the uri parameter letters like <,> into different letters.. So script tag is not executed..

Issue considered as closed..

Regards,

Ahamed
Getting started

Tags


Find what you came for

We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.