Adoxio / xRM-Portals-Community-Edition

The definitive edition of Microsoft Open Source Portals, supported by the experts in portals.
MIT License
107 stars 60 forks source link

Cross-Site Scripting (XSS) on OOB Registration Page #122

Open mbtomlin opened 4 years ago

mbtomlin commented 4 years ago

I've been made aware of a Cross-Site Scripting (XSS) vulnerability on the oob registration button. The partial URL is Account/Login/Register?returnUrl=%2F

Has anyone else experienced this? If so, is it hard to fix or should I just roll my own registration page? Thanks.

amervitz commented 4 years ago

A fix contributed to this project would be ideal. If you'd like to discuss the specifics of the issue before making changes please write to me via the LinkedIn profile I have listed in my GitHub profile. This will help to avoid publically disclosing anything potentially sensitive prior to a fix being available.