Issues » XSS on "page not found .jsp"

Issue: SI-27
Date: Sep 23, 2014, 8:00:00 AM
Severity: Low
Requires Admin Access: No
Fix Version: 3
Credit: Elar Lang / elar -at - clarifiedsecurity.com
Description:

 GET Parameter "url" is displayed back to output without proper escaping.  

Mitigation:

Properly escape the url and hostId parameters

References

https://github.com/dotCMS/core/issues/6353