Quantcast
Channel: Adobe Community : Popular Discussions - RoboHelp
Viewing all articles
Browse latest Browse all 42510

whnjs.htm javascript file and cross-site scripting - security concerns

$
0
0

Hello. Our internal auditors found a serious security issue because of a javascript file generated by RoboHelp in the WebHelp output. The file they identified was whnjs.htm. Here's the description:

 

This page has javascript which sets a frame on the page to the hash of the URL. This can be used as an

injection point for cross site scripting.

POC: https://xxx.xxx/WebHelp/whnjs.htm#javascript:alert(1) //

Internet Explorer only.

 

Does this mean anything to anyone here? I'm using RH9. I'm hoping just an upgrade to v11 will fix this, as I can easily justify that cost with an issue like this.

 

Thanks, Josh


Viewing all articles
Browse latest Browse all 42510

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>