Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-42269 Review all new events introduced in 2.6dev
  3. MDL-42584

there should be no user submitted html text in event description

XMLWordPrintable

    • Icon: Sub-task Sub-task
    • Resolution: Fixed
    • Icon: Minor Minor
    • 2.6
    • 2.6
    • Events API
    • BACKEND Sprint 6

      If there is user submitted text in event description we need to deal with XSS somehow, I guess it would be better to use only integers and safe strings there for now until we decide how to deal with this in logging and reports...

      Affected events:

      • blog_entry_created
      • blog_entry_deleted (collides with record in other field)
      • blog_entry_updated (incorrect single quotes)
      • course_module_created (modulename is ok)
      • course_module_updated
      • user_deleted
      • course_module_viewed (not sure about the 'content')

      Note: this is a minor issues because we can change descriptions at any time...

            rajeshtaneja Rajesh Taneja
            skodak Petr Skoda
            Ankit Agarwal Ankit Agarwal
            Marina Glancy Marina Glancy
            Marina Glancy Marina Glancy
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.