A story about a XSS vulnerability
Posted by jonasbn on June 12, 2009
0 comments
I got a mail forwarded from my current manager. A security scan in relation to our PCI certification had flagged a functionality as insecure, on a medium level. The scanning tool was able to post URI encoded strings, which could be evaluated as working Javascript. This would enable a malicious user to manipulate with the [...]