Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Done
-
6.3.4
-
Xporter - 6.5.0 Sprint 5
-
Description
The path parameter at Scheduled Actions of Scheduled Report setting is not encoded html, leads to the Administrator user who can edit the setting can xss attack to System Administrator or other Administrator user.