mitcho / shibboleth

WordPress Shibboleth plugin
24 stars 23 forks source link

Filter login URLs to prevent XSS attack. #17

Closed dsXLII closed 8 years ago

dsXLII commented 8 years ago

My team's security folks found that JavaScript injection was possible via the login form:

/wp-login.php?21c66"> Githubissues.

  • Githubissues is a development platform for aggregating issues.