-
Type:
Bug
-
Status: Open
-
Priority:
Medium
-
Resolution: Unresolved
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: None
-
Labels:
-
Environment:Production
-
Bug Severity:Low
-
Module:BenAdmin - Security
-
Reported by:Harbinger
[Security Test]
{Cross Site Scripting}
Server side validations are missing on First name last name filed on Add child and Add Spouse pages.
Error get displayed while adding script after bypassing the client side validation.
Test Environment: Production - VM 208...
Tool Used : Tamper Data
Malicious user can enter any scripts through application to generate Server Errors.
Field | Original Value | New Value |
---|---|---|
Module | Parent values: BenAdmin(10100) | Parent values: BenAdmin(10100)Level 1 values: Security(10112) |
Severity | Medium [ 13102 ] |
Issue Category | EBS [ 10350 ] | Harbinger [ 10700 ] |
Issue Category | Harbinger [ 10700 ] | Data Audit [ 18400 ] |
Issue Category | Data Audit [ 18400 ] | Harbinger [ 10700 ] |
Bug Severity | Low [ 16703 ] |
Labels | Security |
Environment_New | Production [ 18442 ] |
Link | This issue relates to DEV-13718 [ DEV-13718 ] |