xss

  1. W

    XSS Problem on Error Page

    I have two PVE nodes on v8.3.3 kernel 6.8.4-2-pve both showing XSS problems. Going to https://[node fqdn/node ip]/%22%3E%3Cscript%3Ealert(document.domain)%3C/script%3E.html causes a popup with the URL, confirming an XSS problem. Whatever is doing the error pages where the passed in URL is echoed...