MatissJanis / oc-testimonials

OctoberCMS testimonial plugin (Mja.Testimonials).
2 stars 6 forks source link

Bug: XSS security vulnerability #13

Open MilosStanic opened 4 years ago

MilosStanic commented 4 years ago

Hi, I've been using the plugin for a couple of years now. I just had a hacking attempt. Please find attached screenshots of injected scripts into the database. Please try to issue an update with sanitized inputs. Thanks! Screenshot_290 Screenshot_291

MatissJanis commented 4 years ago

Hey @MilosStanic

Thanks for bringing this issue up. I'm currently very busy, so won't have much time to take a look at this, however this is an open-source project and you're more than welcome to submit a Pull Request with the fix.