zyx0814 / dzzoffice

dzzoffice
GNU Affero General Public License v3.0
3.88k stars 810 forks source link

Potential XSS Vulnerability #173

Open fschuckert opened 3 years ago

fschuckert commented 3 years ago

There is a potential XSS vulnerability in dzz/attach/ajax.php using the 'editorid' parameter.