TermPortal solve XSS attack vectors

XMLWordPrintable

    • High
    • None
    • Hide
      7.41.0: Correct some string sanitations and fixed some translations
      7.39.1: Fixed some XSS vulnerabilities in Termportal
      Show
      7.41.0: Correct some string sanitations and fixed some translations 7.39.1: Fixed some XSS vulnerabilities in Termportal
    • None

      Problem

      Certain XSS scenarios are currently possible with user-input data - in Translate5 editor's right-side TermPortlet, and across many places in TermPortal (search results, query autocomplete, filter window, active filters, etc)

      Solution

      All html entities within user-input data should be escaped prior using in UI - both in TermPortlet and TermPortal

            Assignee:
            Pavel Perminov
            Reporter:
            Pavel Perminov
            None
            None
            Thomas Lauria
            Stephan Bergmann, Sylvia Schumacher
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved:
              None
              None