-
Bug
-
Resolution: Done
-
Critical
-
4.2.0.GA_CP09, 4.3.0.GA_CP08
-
None
-
Release Notes
-
-
Documented as Resolved Issue
The Seam 2.x actionOutcome parameter issue (JBPAPP-4714, JBPAPP-4717) affects also to some degree Seam 1.x. The injected code however cannot contain method parameters, so it's probably harmless, but steps to sanitize it should be taken.
For example in the booking application following code can be used to retrieve user's password (in the address bar)
http://localhost:8080/seam-booking/home.seam?actionOutcome=/x.html?password%3d%23