getgrav / grav-plugin-login

Grav Login Plugin
http://getgrav.org
MIT License
44 stars 54 forks source link

XSS in /forgot_password #298

Closed Misha-N closed 1 year ago

Misha-N commented 1 year ago

Hello, i found that there is reflected XSS vulnerability in /forgot_password end. If I send request with in it, withou client side validation, script is returned in response and is perfomed on client side. I did not find any solution how to fix it, can you help me with that ? :)

Thank you, Mike

rhukster commented 1 year ago

Please follow this process to report security issues.

https://learn.getgrav.org/17/security/reports

Thanks!