Skip to end of banner
Go to start of banner

Errata - 4.2.0 and earlier Javascript vulnerability

Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Next »

Unfortunately there is an issue with link creation in the GUI with Open-AudIT Community.

If a bad value is passed to the routine via a URL, javascript code can be executed.

This requires the user be logged in to Open-AudIT Community to trigger.

This fix will be included in the next release, however for those that wish to patch it straight away, download the attached file and place in:

Linux - /usr/local/open-audit/code_igniter/application/helpers/output_helper.php
Windows - c:\xampp\open-audit\code_igniter\application\helpers\output_helper.php

Apologies for any inconvenience caused.

  • No labels