<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Gravity Support Forums Topic: Reflected Cross-Site Scripting (XSS) Vulnerabilities</title>
		<link>https://legacy.forums.gravityhelp.com/topic/reflected-cross-site-scripting-xss-vulnerabilities</link>
		<description>Gravity Support Forums Topic: Reflected Cross-Site Scripting (XSS) Vulnerabilities</description>
		<language>en-US</language>
		<pubDate>Mon, 20 Apr 2026 03:24:41 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.1</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>https://legacy.forums.gravityhelp.com/search.php</link>
		</textInput>
		<atom:link href="https://legacy.forums.gravityhelp.com/rss/topic/reflected-cross-site-scripting-xss-vulnerabilities" rel="self" type="application/rss+xml" />

		<item>
			<title>Alan Chapman on "Reflected Cross-Site Scripting (XSS) Vulnerabilities"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/reflected-cross-site-scripting-xss-vulnerabilities#post-52806</link>
			<pubDate>Sun, 18 Mar 2012 23:46:32 +0000</pubDate>
			<dc:creator>Alan Chapman</dc:creator>
			<guid isPermaLink="false">52806@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;I'm using Sitelock and they picked up xss vulernabilities on my drop down fields can you help?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>parthenon on "Reflected Cross-Site Scripting (XSS) Vulnerabilities"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/reflected-cross-site-scripting-xss-vulnerabilities#post-51742</link>
			<pubDate>Thu, 08 Mar 2012 11:24:10 +0000</pubDate>
			<dc:creator>parthenon</dc:creator>
			<guid isPermaLink="false">51742@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Thanks for the fix.&#60;br /&#62;
The Qualys scan is passing now.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Alex Cancado on "Reflected Cross-Site Scripting (XSS) Vulnerabilities"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/reflected-cross-site-scripting-xss-vulnerabilities#post-51510</link>
			<pubDate>Tue, 06 Mar 2012 18:00:20 +0000</pubDate>
			<dc:creator>Alex Cancado</dc:creator>
			<guid isPermaLink="false">51510@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;I was able to pinpoint and address both of these vulnerabilities. They will be available this afternoon or tomorrow as part of the 1.6.3.2 release.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Alex Cancado on "Reflected Cross-Site Scripting (XSS) Vulnerabilities"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/reflected-cross-site-scripting-xss-vulnerabilities#post-51429</link>
			<pubDate>Tue, 06 Mar 2012 10:24:11 +0000</pubDate>
			<dc:creator>Alex Cancado</dc:creator>
			<guid isPermaLink="false">51429@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Thanks for pointing these out. Let me take a look at it and see what i can do to solve these vulnerabilities. I will keep you posted
&#60;/p&#62;</description>
		</item>
		<item>
			<title>parthenon on "Reflected Cross-Site Scripting (XSS) Vulnerabilities"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/reflected-cross-site-scripting-xss-vulnerabilities#post-50926</link>
			<pubDate>Wed, 29 Feb 2012 11:55:27 +0000</pubDate>
			<dc:creator>parthenon</dc:creator>
			<guid isPermaLink="false">50926@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;My client is using Qualys to scan their site and their tool is reporting two XSS issues on a form I created.&#60;/p&#62;
&#60;p&#62;One of the issues is with a radio buttons field with 'Enable &#34;other&#34; choice' checked.&#60;/p&#62;
&#60;p&#62;&#60;code&#62;&#38;lt;input name=&#38;#39;input_19_other&#38;#39; type=&#38;#39;text&#38;#39; value=&#38;#39;Male &#38;lt;script&#38;gt;_q_q=random()&#38;lt;/script&#38;gt;&#38;#39; onfocus=&#38;#39;jQuery(this).prev(&#38;quot;input&#38;quot;).attr(&#38;quot;checked&#38;quot;, true); if(jQuery(this).val() == &#38;quot;Other&#38;quot;) { jQuery(this).val(&#38;quot;&#38;quot;); }&#38;#39; onblur=&#38;#39;if(jQuery(this).val().replace(&#38;quot; &#38;quot;, &#38;quot;&#38;quot;) == &#38;quot;&#38;quot;) { jQuery(this).val(&#38;quot;Other&#38;quot;); }&#38;#39; tabindex=&#38;#39;104&#38;#39;  /&#38;gt;&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;The other issue is with a hidden input.&#60;/p&#62;
&#60;p&#62;&#60;code&#62;&#38;lt;input type=&#38;#39;hidden&#38;#39; name=&#38;#39;gform_ajax&#38;#39; value=&#38;#39;form_id=7&#38;amp;title=&#38;amp;description= &#38;lt;script&#38;gt;_q_q=random()&#38;lt;/script&#38;gt;&#38;#39; /&#38;gt;&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;Is there a fix for this?  Is this a known issue?
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
