| Build Number | Database | OS |
| :—-3025—–: | :—-MySQL—-: | :—Server 2022——: |
| {Put Build No Here} | {Put DB Here} | {Put OS Here} |
A “Friendly” user just code injected me with the below line which put some xml in the browser. Since I can’t see anything like this I’m assuming he’s using some developer tools to see the raw html that AwareIM generates and - like me, just stuck the https://[redacted domain name]:8443 in front of it. So my question is - how can I stop this happening
https://redacted:8443/AwareIM/urlRequest.aw?actionType=run_query_action&query_string=FIND+Products+WHERE+Products.WebSales%3D%27Yes%27+OR+%271%27%3d%271%27&widgetId=AW_CUSTOM_QUERY_96356&query_name=WebSalesMobile&take=20&skip=0&start=0&pageSize=20
Which produced some xml in the browser
<root>
<run_query_action_return><run_query_action_success>
<dataset>
<total>113</total>
<row>
<id>98641</id>
<BAS_REF_VALUE>Products:98641</BAS_REF_VALUE>
<ProductName org_value="">Single flight lesson</ProductName>
<VoucherText org_value=""/>
<RRP org_value="">75.00</RRP>
<WebImage org_value=""><img src="" border="0" vspace="0" align="absmiddle" width="100%" height="100%" ></WebImage>
<BAS_PROTECTED/>
<BAS_OPER_APPLICABILITY/>
</row>