Uploaded image for project: 'Click'
  1. Click
  2. CLK-726

bypass_validation opens security hole

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.2.0
    • 2.3.0-M1
    • core
    • None

    Description

      An attacker can easily bypass form validation by setting the hidden field "bypass_validation" to true. A call to form.isValid() returns true though the validators have not been run. If the software relies on the form validators, its easy to get "evil" data in the application.

      Attachments

        Activity

          People

            sabob Bob Schellink
            moe Moritz Kammerer
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: