Discussions
Stay up-to-date with the latest news from NetSuite. You’ll be in the know about how to connect with peers and take your business to new heights at our virtual, in-person, on demand events, and much more.
Now is the time to ask your NetSuite-savvy friends and colleagues to join the NetSuite Support Community! Refer now! Click here to watch and learn more!
Are NS websites PCI compliant? Problem with IFrames
We recently received a notice saying that Netsuite is not PCI compliant because it allows WebApp Cross Site Scripting through IFrame.
They sent the following URL:
Sample URL showing Iframe
To be PCI compliant, when someone tries to put the above IFrame code in the URL, netsuite should return a 404 page but instead it returns a page with an Iframe.
Does anyone from Netsuite can confirm if this is in fact a security issue and how can it be addressed?
Thank you.
0