Skip to main content

This site requires you to update your browser. Your browsing experience maybe affected by not having the most up to date version.

SS-2016-015: XSS In OptionsetField and CheckboxSetField

Severity:
Low (?)
Identifier:
ss-2016-015
Versions Affected:
3.1.19, 3.2.4, 3.3.2. 3.4.0
Versions Fixed:
3.1.20, 3.2.5, 3.3.3. 3.4.1
Release Date:
2016-08-15

List of key / value pairs assigned to OptionsetField or CheckboxSetField do not have a default casting assigned to them. The effect of this is a potential XSS vulnerability in lists where either key or value contain unescaped HTML.