Re: [Tiki-devel] Security Holes

luciash via TikiWiki-devel <[email protected]>
Newsgroups gmane.comp.cms.tiki.devel
Message-ID <[email protected]>
Hi Volker,

if you believe you found a security hole please send the details to 
security AT tiki.org (and do not disclose it here publicly in devel 
mailing list).

Thanks!

luci


On 26.07.2021 13:32, Volker Wysk wrote:
> Hi Luciash!
>
> Am Montag, den 26.07.2021, 11:27 +0200 schrieb luciash via TikiWiki-devel:
>> Hi Volker,
>>
>> thanks for your contribution!
>>
>> The implications are if you don't use the proper filter you might introduce a security flaw (security hole) so it's always needed to use the appropriate filter or filter the field to a number only and make the units to be selected (e.g. in a drop down) from a predefined list of options.
> I've noticed a security hole. In a global variable, you can put any HTML
> code. You don't need to be the admin for this. It gets active, when the
> contents of the variable is displayed. On the other hand, the HTML plugin is
> restricted for security reasons...
>
> Bye
> Volker
>
>> luci
>>
>>
>>
>> On 23.07.2021 19:20, Volker Wysk wrote:
>>> Hi!
>>>
>>> I've improved the Font Plugin. In the previous version, the font size
>>> could only be specified in pixels. I've made it possible to specify it
>>> in any of the ways, in which font sizes can be specified by the "font-
>>> size" CSS style. See here:
>>>
>>> https://www.w3.org/TR/CSS2/fonts.html#propdef-font-size
>>>
>>> Now you can say "{FONT(size=125%)}...{FONT}" or
>>> "{FONT(size=1.5em)}...{FONT}" or ...
>>>
>>> The changes were small. However, I've removed the "filter" property
>>> from the "size" argument. I don't understand the implications of this
>>> fully yet.
>>>
>>> I think the improved version should go into Tiki.  :-)  I'll update the
>>> documentation.
>>>
>>> The new version is attached.
>>>
>>> Cheers,
>>> Volker
>>>
>>>
>>>
>>> _______________________________________________
>>> TikiWiki-devel mailing list
>>> [email protected]
>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
>> _______________________________________________
>> TikiWiki-devel mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.