Improve segment content sanitation to prevent XSS attacks (finding H1.1)

XMLWordPrintable

    • Critical
    • Solve an XSS attack vector in segment content.

      problem

      Segment editing allows XSS attacks. Ordinary attack vectors (img onload, script tags) are recognized and prevented already. 

      Additional vectors were found. See PDF in linked TS Issue. 

      solution

      Include a more sophisticated lib to filter out the described, other possible attack vectors. Allow only the needed HTML in segment content.

       

            Assignee:
            Thomas Lauria
            Reporter:
            Thomas Lauria
            Leon Kiz
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: