OpenConext / OpenConext-myconext

A (guest) IdP for OpenConext
https://eduid.nl/
4 stars 8 forks source link

SC-10-010 WP2: Stored XSS via username cookie on eduID login portal (High) #398

Closed phavekes closed 2 weeks ago

phavekes commented 2 weeks ago

This issue is imported from pivotal

phavekes commented 2 weeks ago

https://github.com/OpenConext/OpenConext-myconext/commit/a497523e15210206a9193bb5a6411d1dfc364d6c (Okke Harsta - Aug 25, 2022)