-
Bug
-
Resolution: Fixed
-
Critical
-
None
-
Platform: All, OS: All
Hudson 1.295 allows user to type cross-site scriptings(xss) on search-box.
Example:
http://hudson-host/search/?
q=<script>alert('script');</script>&json={"q":+"<script>alert('oops');</script>"
}