Uploaded image for project: 'VCL'
  1. VCL
  2. VCL-808

vcld allows user values that contain HTML which is not cleaned on web interface

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Won't Fix
    • 2.3.2
    • 2.5
    • vcld (backend)
    • None

    Description

      put in HTML/Javascript for a users first name, it makes it into the database and is displayed and executed on the web interface

      Example: ./vcld -setup
      Add user with a firstname of "<b>Bol</b>"
      Lookup the user on the web interface

      Attachments

        Activity

          People

            Unassigned Unassigned
            vollmerk Karl Vollmer
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: