#7571 XSS? on forum

unreleased
invalid
nobody
None
Forum
nobody
2015-03-10
2014-07-16
Shuji Sado
No

Discussion

  • Dave Brondsema

    Dave Brondsema - 2014-07-16
    • status: open --> invalid
     
  • Dave Brondsema

    Dave Brondsema - 2014-07-16

    I see no XSS here. If you have an example where javascript runs, please provide it. In this case, input form fields are rendered, but no javascript runs. See also [#4644] for removing form fields from the HTML whitelist.

     

    Related

    Tickets: #4644


Log in to post a comment.