XSS/JS filter hitting when saving a custom Smart template file
- Status
- Pending
- Subject
- XSS/JS filter hitting when saving a custom Smart template file
- Version
- 2.x
- Category
- Error
- Feature
- Templates (Smarty)
- Resolution status
- New
- Submitted by
- Carsten Schmitz
- Lastmod by
- Carsten Schmitz
- Rating
- Description
When saving a Smarty template for a specific theme using the TikiWiki admin GUI then all kinds of fake tags
</x> are inserted in javascript.
It seems that the XSS filter is hitting here. It should not since it is a super-admin function and should not be XSS-filtered, of course.I tried to edit tiki-editpage.tpl when this occured.
- Importance
- 4
- Priority
- 20
- Demonstrate Bug on Tiki 19+
-
This bug has been demonstrated on show2.tiki.org
Please demonstrate your bug on show2.tiki.org
Show.tiki.org is not configured properlyThe public/private keys configured to connect to show2.tiki.org were not accepted. Please make sure you are using RSA keys. Thanks.
- Demonstrate Bug (older Tiki versions)
-
This bug has been demonstrated on show.tikiwiki.org
Please demonstrate your bug on show.tikiwiki.org
Show.tiki.org is not configured properlyThe public/private keys configured to connect to show.tikiwiki.org were not accepted. Please make sure you are using RSA keys. Thanks.
- Ticket ID
- 1992
- Created
- Thursday 28 August, 2008 09:23:56 UTC
by Unknown - LastModif
- Thursday 28 August, 2008 09:23:56 UTC