[ZendTo] XSS

Chris Venter chris.venter1 at gmail.com
Tue Mar 1 19:14:53 GMT 2016


Hi

Our security audit has highlighted a possible reflected cross site
scripting error on the pickup.php page,to test we ran

https://server_name/pickup/php?emailAddr=test" /><script>alert('XSS
Test')</script>

Can anyone else confirm if this is an issue?

Thanks
CJ
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ecs.soton.ac.uk/pipermail/zendto/attachments/20160301/b31b03a5/attachment.html 


More information about the ZendTo mailing list