[RESOLVED] (2.9.5rc36) XSS / CORS problem

Bug reports and enhancement requests
Post Reply
Zeitkind
Posts: 2
Joined: Mon Nov 21, 2016 5:43 pm

[RESOLVED] (2.9.5rc36) XSS / CORS problem

Post by Zeitkind »

Hiho,
since I installed the recent developement version 35+36 I have problems with eg. ebay not showing all content:
Quellübergreifende (Cross-Origin) Anfrage blockiert: Die Gleiche-Quelle-Regel verbietet das Lesen der externen Ressource auf http://rover.ebay.de/roverclk/0/0/9?trk ... s%3D100005. (Grund: CORS-Kopfzeile 'Access-Control-Allow-Origin' fehlt).
Page eg.: http://www.ebay.de/itm/10PCS-RGB-Tea-Fl ... SwkNZUgAez
It works with the stable version, FF even does show the content with NoScript stable fresh install with nothing allowed @ebay yet.

FF50, OS X, noscript(2.9.5rc36). Also no luck if I disable ABE and XSS, won't load the description.
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:50.0) Gecko/20100101 Firefox/50.0
Zeitkind
Posts: 2
Joined: Mon Nov 21, 2016 5:43 pm

Re: (2.9.5rc36) XSS / CORS problem

Post by Zeitkind »

Seems to be fixed with the new rc1.
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:50.0) Gecko/20100101 Firefox/50.0
Post Reply