View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0004979 | SOGo | Web Mail | public | 2020-03-06 06:12 | 2020-03-06 17:17 |
| Reporter | tzrj | Assigned To | francis | ||
| Priority | high | Severity | major | Reproducibility | N/A |
| Status | resolved | Resolution | fixed | ||
| Product Version | 4.3.0 | ||||
| Fixed in Version | 4.3.1 | ||||
| Summary | 0004979: Stored XSS in Web Mail | ||||
| Description | Stored XSS at Web Mail (Works on Chrome Latest) | ||||
| Steps To Reproduce | Send mail to mailbox using SOGo Web Mail with the payload | ||||
| Tags | No tags attached. | ||||
|
sogo: master d1dbceb4 2020-03-06 12:14 Details Diff |
fix(mail): remove onpointerrawupdate event handler from HTML messages Fixes 0004979 |
Affected Issues 0004979 |
|
| mod - UI/MailPartViewers/UIxMailPartHTMLViewer.m | Diff File | ||
| mod - UI/Templates/MailerUI/UIxMailEditor.wox | Diff File | ||
| mod - UI/WebServerResources/js/Common/sgAutogrow.directive.js | Diff File | ||
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2020-03-06 06:12 | tzrj | New Issue | |
| 2020-03-06 17:16 | francis | Changeset attached | => sogo master d1dbceb4 |
| 2020-03-06 17:16 | francis | Assigned To | => francis |
| 2020-03-06 17:16 | francis | Resolution | open => fixed |
| 2020-03-06 17:17 | francis | Status | new => resolved |
| 2020-03-06 17:17 | francis | Fixed in Version | => 4.3.1 |