From Social Pudu, 5 Years ago, written in Plain Text.
Embed
  1. fileClient DOM XSS\Path 2:
  2. Method && at line 4907 of webapp/src/main/webapp/media/lst-self-register-form/lst-self-register-form/lstself-register-form.core.pf.js gets user input for the location element. This element’s value then flows through client-side code without being properly sanitized or validated and is eventually displayed to the user in Promise at line 5151 of webapp/src/main/webapp/media/lst-self-register-form/lst-self-register-form/lst-self-registerform.core.pf.js.This may enable a DOM XSS attack.
  3.  
  4.  
  5. Source
  6. File: webapp/src/main/webapp/media/lst-self-register-form/lst-self-register-form/lst-self-register-form.core.pf.js
  7.  
  8. Line: 4935
  9. Object: location
  10.  
  11. Destination
  12. File: webapp/src/main/webapp/media/lst-self- register-form/lst-self-register-form/lst- self-register-form.core.pf.js
  13. Line: 5153
  14. Object: write
  15.  
  16.  
  17.  
  18. (same as the first issue, but one under auto-generated folder)
  19. webapp/src/main/webapp/media/auto-generated-dist/lst-self-register-form/lst- self-register-form/lst-self-register-form.core.pf.js
  20.