| Issue: |
|
|---|---|
| Date: |
|
| Severity: | Low |
| Requires Admin Access: | No |
| Fix Version: | 3 |
| Credit: | Elar Lang / elar -at - clarifiedsecurity.com |
| Description: |
GET Parameter "url" is displayed back to output without proper escaping. |
| Mitigation: |
Properly escape the url and hostId parameters |
| References |
https://github.com/dotCMS/core/issues/6353 |