Ticket #2140 (closed defect: fixed)
Editor widget vulnerable to XSS attacks
| Reported by: | guest | Owned by: | peller |
|---|---|---|---|
| Priority: | high | Milestone: | 1.2 |
| Component: | Editor | Version: | 0.4.1 |
| Severity: | major | Keywords: | |
| Cc: |
Description
It seems that the editor is bent on executing javascript that a user has entered into an editor and saved. Even if I replace the <script> tags with <script> in the datbase, it executes it when it is displayed in the browser. Dojo should provide a method to disallow user entered javascript from executing.
Change History
Note: See
TracTickets for help on using
tickets.