Uploaded image for project: 'Apache Roller'
  1. Apache Roller
  2. ROL-1196

Safe comments: strip HTML from comment name, URL and email addresses

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.3
    • 2.3.1
    • Comments
    • None
    • Less than 1 hour plus release overhead

    Description

      See title.

      We allow users to use HTML in comment body, but we strip all but a "safe subset" of HTML when we display the coment. However, we don't do any HTML stripping safe-subsetting on the comment name, HTML or url. That leaves Roller open to XSS attacks by commenters.

      Attachments

        Activity

          People

            djohnson David Johnson
            djohnson David Johnson
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: