script injection

gsiak <gsiak-S0/[email protected]>
Newsgroups gmane.comp.web.zope.plone.devel
Message-ID <[email protected]>
We are using Plone 3.3.5 with cyn.in template in a productive environment as
an intranet solution. 

During a security check, we regognized, that it is possible to implement
'script' tags in objects dublin core (title, description, tags), which will
be executed during display. The 'script' tag is excluded by filter
configuration, but this will not take place in this cases.

Can someone help me what to do to prevent such an injection by useres adding
new content? 



--
View this message in context: http://plone.293351.n2.nabble.com/script-injection-tp7568930.html
Sent from the Core Developers mailing list archive at Nabble.com.

------------------------------------------------------------------------------
DreamFactory - Open Source REST & JSON Services for HTML5 & Native Apps
OAuth, Users, Roles, SQL, NoSQL, BLOB Storage and External API Access
Free app hosting. Or install the open source package on any LAMP server.
Sign up and see examples for AngularJS, jQuery, Sencha Touch and Native!
http://pubads.g.doubleclick.net/gampad/clk?id=63469471&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.