Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Amir Khan 1282 posts 2739 karma points
    Oct 15, 2014 @ 18:12
    Amir Khan
    0

    XSS Vulnerability?

    I ran a penetration test against one of my sites and am coming back with an XSS vulnerability on a url with a contour form on it. The Paramter listed is the a string that looks like a GUID, but isn't the GUID of the form.

    Does anyone know why this would happen and how to remediate it?

    Thanks,
    Amir

  • Amir Khan 1282 posts 2739 karma points
    Oct 15, 2014 @ 18:50
    Amir Khan
    0

    So I think this is realated to the file upload field on the form. Is it possible to validate the file extension? I don't see an validation option in the upload field datatype.

    Thanks!
    Amir

Please Sign in or register to post replies

Write your reply to:

Draft