PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

Problem Summary: Security vulnerabilities when uploading an HTML file in the system.

edited Mar 30, 2022 3:52PM in PeopleTools and Lifecycle Management - PSFT (MOSC) 1 commentAnswered

We currently can upload an HTML file as an attachment from the Personal Details\Additional Information\Marital Status screen. Our Security group has brought to our attention that these files can be embedded with JavaScript, presenting a security vulnerability. Please see the following questions below:

  • Are there potential risks to the system when uploading an HTML file?
  • Are there any known issues with uploading this file type into the system?
  • Does the software validate for any embedded scripting?


Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center