Skip to main content
Participating Frequently
June 7, 2013
Question

DOM Based Cross-Site Scripting issue in RoboHelp 10

  • June 7, 2013
  • 2 replies
  • 1922 views

We're using a WebHelp system originally deplyed using RoboHelp 9.0.2.271, and a recent security scan revealed the DOM based cross-site scripting issue.

I recently upgraded to RoboHelp 10, migrated my help system to this version, and redeployed the system, but our security scan is still detecting the cross-scripting vulnerability in WebHelp. Wasn't this issue resolved in RoboHelp 10?

Thanks

This topic has been closed for replies.

2 replies

Willam van Weelden
Inspiring
June 9, 2013

Hi,

What XSS vulnerability are you talking about? It’s hard to know whether an issue is fixed when we don’t know what issue you’re talking about.

Greet,

Willam

Kimota12Author
Participating Frequently
June 10, 2013

Here's an example of one of the issues the security scan caught:

Willam van Weelden
Inspiring
June 17, 2013

Hi,

I’m not a security expert, but this script reads the URL of the current topic and redirects to the current topic with a bookmark. This is needed for when the same topic is used in multiple locations in the TOC.

I’ll ask around about this security issue.

Greet,

Willam

Jeff_Coatsworth
Community Expert
Community Expert
June 7, 2013

You should contact Adobe Support with your concerns and specifics of the issue your security guys are finding. You may have to use the Multiscreen HTML5 SSL to get around issues with frames.