EmicoEcommerce / Magento2Tweakwise-archived

Magento 2 module for Tweakwise integration
Other
9 stars 25 forks source link

Disable Reflected XSS on de slider confguration #226

Closed Hnto closed 2 years ago

Hnto commented 2 years ago

The Slider configuration contains the current url, which could be escaped adding a single quote '.

This way it was possible to add reflected XSS in the URL For obvious reasons I will not add the URL's used here.