Forum

Cross site scriptin...
 
Notifications
Retirer tout

Cross site scripting issue during installation

4 Posts
2 Utilisateurs
0 Reactions
1,015 Vu
(@berthelemy)
Posts: 8
Active Member
Début du sujet
 
[#9528]

Bonjour / Hi,

I'm installing on a shared hosting site (PlanetHoster). The firewall there prevented me from saving the configuration file. I could only proceed by switching off the rule that was being invoked (see below)

Am I safe to continue with this firewall rule switched off?

Merci,

Mark

Firewall report

ID : 341256Severity: CRITICALLabel : -info : Atomicorp.com WAF Rules: Possible Cross Site Scripting attack (detectXSS)message : Access denied with code 403 (phase 2). detected XSS using libinjection.Request InfoDate : 18/07/2024, 20:50 GMT+2HTTP method: POSTClient IP: 89.91.136.172Port: 2080Protocol: HTTP/1.1Uri: /tool/configCheck.php?destinationWidth=1038&destinationHeight=82.5&isIE=&xhrPostDestination=configResultDiv&xhrPostIsResultMessage=false&xhrPostValidationType=&xhrPostTimestamp=1721328614008&csrfToken=Response status : 403


 
Posté : 18 Juil PM 23:077
(@babynus)
Posts: 14952
Membre Admin
 

This question is out of ProjeQtOr scope.
Please ask your web hoster.


 
Posté : 19 Juil PM 20:077
(@berthelemy)
Posts: 8
Active Member
Début du sujet
 

Thanks. I will.

I was more concerned about why Projeqtor was triggering the XSS warning?


 
Posté : 22 Juil PM 18:077
(@babynus)
Posts: 14952
Membre Admin
 

Possibly the install process for your hosted server is looking like a XSS attack.
If your hoster uses control interface such as CPanle, you may use Softaculous image of ProjeQtOr to install it fluently.


 
Posté : 23 Juil PM 12:077
Share:
Retour en haut