Re: script injection
Nathan Van Gheem <[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.devel |
|---|---|
| Message-ID | <CAL8hw9EGJf7H4hHiuJcky5oWitDBhcprt=Gkej_DruB9-pfUuA@mail.gmail.com> |
This doesn't below on plone-dev and the responsible way to report a security issue is to a private mailing, preferably security, list. But to answer your question, cyn.in likely doesn't escape html when rendering those fields. Maybe report the issue: https://github.com/collective/cyn.in On Mon, Nov 18, 2013 at 7:17 AM, gsiak <gsiak-S0/[email protected]> wrote: > We are using Plone 3.3.5 with cyn.in template in a productive environment > as > an intranet solution. > > During a security check, we regognized, that it is possible to implement > 'script' tags in objects dublin core (title, description, tags), which will > be executed during display. The 'script' tag is excluded by filter > configuration, but this will not take place in this cases. > > Can someone help me what to do to prevent such an injection by useres > adding > new content? > > > > -- > View this message in context: > http://plone.293351.n2.nabble.com/script-injection-tp7568930.html > Sent from the Core Developers mailing list archive at Nabble.com. > > > ------------------------------------------------------------------------------ > DreamFactory - Open Source REST & JSON Services for HTML5 & Native Apps > OAuth, Users, Roles, SQL, NoSQL, BLOB Storage and External API Access > Free app hosting. Or install the open source package on any LAMP server. > Sign up and see examples for AngularJS, jQuery, Sencha Touch and Native! > http://pubads.g.doubleclick.net/gampad/clk?id=63469471&iu=/4140/ostg.clktrk > _______________________________________________ > Plone-developers mailing list > Plone-developers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org > https://lists.sourceforge.net/lists/listinfo/plone-developers > -- Nathan Van Gheem Solutions Architect Wildcard Corp ------------------------------------------------------------------------------ DreamFactory - Open Source REST & JSON Services for HTML5 & Native Apps OAuth, Users, Roles, SQL, NoSQL, BLOB Storage and External API Access Free app hosting. Or install the open source package on any LAMP server. Sign up and see examples for AngularJS, jQuery, Sencha Touch and Native! http://pubads.g.doubleclick.net/gampad/clk?id=63469471&iu=/4140/ostg.clktrk _______________________________________________ Plone-developers mailing list Plone-developers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/plone-developers