View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0004979 | SOGo | Web Mail | public | 2020-03-06 06:12 | 2020-03-06 17:17 |
Reporter | tzrj | Assigned To | francis | ||
Priority | high | Severity | major | Reproducibility | N/A |
Status | resolved | Resolution | fixed | ||
Product Version | 4.3.0 | ||||
Fixed in Version | 4.3.1 | ||||
Summary | 0004979: Stored XSS in Web Mail | ||||
Description | Stored XSS at Web Mail (Works on Chrome Latest) | ||||
Steps To Reproduce | Send mail to mailbox using SOGo Web Mail with the payload | ||||
Tags | No tags attached. | ||||
sogo: master d1dbceb4 2020-03-06 12:14 Details Diff |
fix(mail): remove onpointerrawupdate event handler from HTML messages Fixes 0004979 |
Affected Issues 0004979 |
|
mod - UI/MailPartViewers/UIxMailPartHTMLViewer.m | Diff File | ||
mod - UI/Templates/MailerUI/UIxMailEditor.wox | Diff File | ||
mod - UI/WebServerResources/js/Common/sgAutogrow.directive.js | Diff File |
Date Modified | Username | Field | Change |
---|---|---|---|
2020-03-06 06:12 | tzrj | New Issue | |
2020-03-06 17:16 | francis | Changeset attached | => sogo master d1dbceb4 |
2020-03-06 17:16 | francis | Assigned To | => francis |
2020-03-06 17:16 | francis | Resolution | open => fixed |
2020-03-06 17:17 | francis | Status | new => resolved |
2020-03-06 17:17 | francis | Fixed in Version | => 4.3.1 |