Uploaded image for project: 'Tuigwaa'
  1. Tuigwaa
  2. TUIGWAA-114

Site,Entity,Column の表示名に <,>,& が入力できる

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 1.0
    • Component/s: None
    • Labels:
      None

      Description

      Site,Entity,Column の表示名に <,>,& が入力できる

      XSS,ognl不正文字の観点から入力を禁止するようにすべき。

        Activity

        Hide
        takishita takishita added a comment -

        Committed revision 1071.

        validate ではじくように修正。

        Show
        takishita takishita added a comment - Committed revision 1071. validate ではじくように修正。
        Hide
        takishita takishita added a comment -

        Committed revision 1073.

        ",\ もはじくように修正

        Show
        takishita takishita added a comment - Committed revision 1073. ",\ もはじくように修正

          People

          • Assignee:
            takishita takishita
            Reporter:
            takishita takishita
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development