Uploaded image for project: 'Magnolia Form Module'
  1. Magnolia Form Module
  2. MGNLFORM-183

XSS vulnerability of form fields - CVE-2013-4759

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Neutral Neutral
    • 1.4.7, 2.0.2
    • 1.4.5, 2.0
    • None
    • None

      MGNLFORM-156 removed escaping from FTL templates because values should be already escaped by HTMLEscapingNodeWrapper.
      But field values are set into model from unwrapped content and later requested for rendering. Therefore aren't escaped.

        Acceptance criteria

              rkovarik Roman Kovařík
              rkovarik Roman Kovařík
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Bug DoR
                  Task DoD