• Dave Cridland's avatar
    OF-836 CVE-2015-6972 MUC service description · 340f0fc9
    Dave Cridland authored
    The mucdesc parameter of muc-service-edit-form.jsp was reflected unescaped in
    the summary view at muc-service-summary.jsp
    
    This was reported by Florian Nivette of Sysdream.
    
    Fixed by escaping on output within muc-service-summary.jsp.
    
    In addition, domain validation was added on input.
    340f0fc9
Name
Last commit
Last update
build Loading commit data...
documentation Loading commit data...
src Loading commit data...
.gitignore Loading commit data...
.travis.yml Loading commit data...
Makefile Loading commit data...
README.md Loading commit data...