Uploaded image for project: 'MusicBrainz Server'
  1. MusicBrainz Server
  2. MBS-10632

Potential XSS injection in form field error messages

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • Editing interface
    • None

      Fix #1361 to MBS-10576 opens for potential XSS injection in form field error messages since the View component assumes error messages are correctly HTML-encoded by the Model-Controller components which proved to be untrue at least once.

      A safer implementation would be to create expandable objects instead of HTML strings and to convey it to the renderer and let it encode every string to HTML.

            Unassigned Unassigned
            yvanzo yvanzo
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:

                Version Package