script injection
gsiak <gsiak-S0/[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.devel |
|---|---|
| Message-ID | <[email protected]> |
We are using Plone 3.3.5 with cyn.in template in a productive environment as an intranet solution. During a security check, we regognized, that it is possible to implement 'script' tags in objects dublin core (title, description, tags), which will be executed during display. The 'script' tag is excluded by filter configuration, but this will not take place in this cases. Can someone help me what to do to prevent such an injection by useres adding new content? -- View this message in context: http://plone.293351.n2.nabble.com/script-injection-tp7568930.html Sent from the Core Developers mailing list archive at Nabble.com. ------------------------------------------------------------------------------ DreamFactory - Open Source REST & JSON Services for HTML5 & Native Apps OAuth, Users, Roles, SQL, NoSQL, BLOB Storage and External API Access Free app hosting. Or install the open source package on any LAMP server. Sign up and see examples for AngularJS, jQuery, Sencha Touch and Native! http://pubads.g.doubleclick.net/gampad/clk?id=63469471&iu=/4140/ostg.clktrk