[MGNLFORUM-81] Forum or page comments posts containing html are not escaped properly in admin interface Created: 06/Mar/09 Updated: 02/Dec/13 Resolved: 06/Mar/09 |
|
| Status: | Closed |
| Project: | Forum (closed) |
| Component/s: | None |
| Affects Version/s: | m1 |
| Fix Version/s: | 1.0 |
| Type: | Bug | Priority: | Major |
| Reporter: | Jan Haderka | Assignee: | Jan Haderka |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Template: |
|
| Acceptance criteria: |
Empty
|
| Date of First Response: |
| Description |
|
Html in forum posts is actually processed while viewing posts in admin interface and is corrupting the display (apart from possibility to craft attack by injecting html that will overlay some ui element and redirect forum moderator so some other site). |
| Comments |
| Comment by Jan Haderka [ 06/Mar/09 ] |
|
Done as of r23280. |
| Comment by Christoph Meier [ 02/Dec/13 ] |
|
closed, since it has resolved a long time ago |