Details
-
Task
-
Resolution: Fixed
-
None
-
Critical
-
Fixed XSS issues in filenames
-
Empty show more show less
Description
problem
What was completely forgotten when implementing TRANSLATE-283 was the possibility that filenames (workfiles / reference files / etc. pp) are also vulnerable for PXSS attacks.
First we need a concept how to fix that, the concept can then go into a new t5dev issue. The issue should be converted into a TRANSLATE-issue right before release, so that we do not publish about security issues before release.
Attachments
Issue Links
- relates to
-
TRANSLATE-3960 Test PXSS in all input fields of the application
- Done