i find xss in url
http://192.168.1.71:8888/rest/getstatus<script>alert(document.cookie)</script>
http://192.168.1.71:8888/rest/getstatus
about xss
i find xss in url
http://192.168.1.71:8888/rest/getstatus<script>alert(document.cookie)</script>
http://192.168.1.71:8888/rest/getstatus
about xss
Please always mention a lucee version. And there is a ticket in lucee and that’s deployed in version 5.3.8.112. Can you please check with this? LDEV-3023
my lucee version is 5.3.7.48
veryfy with 5.3.8.112 is ok,
thank you