Can Data be Modified or Injected Through URL Path Traversal on a Storefront?
(Doc ID 2639980.1)
Last updated on FEBRUARY 25, 2020
Applies to:Oracle Commerce Cloud Service - Version N/A and later
Information in this document applies to any platform.
Determine whether user accessing directly the internal server directories via the store URL https://ccstore-****.oracleoutsourcing.com/ccstore/v1/images/ ? source = / css /../ style.css will cause any issues.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document