atutor/ATutor

Stored XSS in "Real Name" field - My Account

SegfaultMasters opened this issue · 4 comments

Description -
There's no escape being done before printing out the value of Real Name in the My Account page.

ATutor version - v2.2.4

Steps to reproduce -

image11

image6

Please submit a pull request to fix this.

fgeek commented
fgeek commented

Please submit a pull request to fix this.

As a maintainer of this project are you planning to fix this and release new version? I don't think waiting for PRs is correct way to handle security issues (maybe only if this is mentioned clearly in some documentation). Of course that is only my personal opinion, but I can't recommend people to use ATutor if this is the case.

ATutor is no longer maintained.