Bug #71698
closedLink fields accept inline javascript code
100%
Description
javascript:alert(1)
can be submitted for every link field and will be rendered in the frontend passed through typolink. To circumvent that, the URI scheme and prefix "javascript:" will be disallowed per default. The extension "javascript_handler" allows however to bring back that insecure behavior since some installations might rely on it.
Files
Updated by Gerrit Code Review about 9 years ago
- Status changed from New to Under Review
Patch set 1 for branch master of project Teams/Security/TYPO3v4-Core has been pushed to the review server.
It is available at https://review.typo3.org/44803
Updated by Gerrit Code Review about 9 years ago
Patch set 2 for branch master of project Teams/Security/TYPO3v4-Core has been pushed to the review server.
It is available at https://review.typo3.org/44803
Updated by Gerrit Code Review about 9 years ago
Patch set 1 for branch TYPO3_6-2 of project Teams/Security/TYPO3v4-Core has been pushed to the review server.
It is available at https://review.typo3.org/44804
Updated by Gerrit Code Review about 9 years ago
Patch set 3 for branch master of project Teams/Security/TYPO3v4-Core has been pushed to the review server.
It is available at https://review.typo3.org/44803
Updated by Gerrit Code Review about 9 years ago
Patch set 2 for branch TYPO3_6-2 of project Teams/Security/TYPO3v4-Core has been pushed to the review server.
It is available at https://review.typo3.org/44804
Updated by Georg Ringer about 9 years ago
- Status changed from Under Review to Resolved
merged in release branch
Updated by Gerrit Code Review about 9 years ago
- Status changed from Resolved to Under Review
Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/44876
Updated by Georg Ringer almost 9 years ago
- Status changed from Under Review to Resolved
merged in release branch
Updated by Gerrit Code Review almost 9 years ago
- Status changed from Resolved to Under Review
Patch set 1 for branch TYPO3_6-2 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/45265
Updated by Oliver Hader almost 9 years ago
- Status changed from Under Review to Resolved
- % Done changed from 0 to 100
Applied in changeset typo3cms-core:25a1473907f0f4b2bb0147c661981940c57a4555.
Updated by Gerrit Code Review almost 9 years ago
- Status changed from Resolved to Under Review
Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/45277
Updated by Oliver Hader almost 9 years ago
- Status changed from Under Review to Resolved
Applied in changeset typo3cms-core:de1755a6dcff9b037c6d5a1fa340ba100aff054a.
Updated by Nicole Cordes almost 9 years ago
- File deleted (
javascript_handler.zip)
Updated by Nicole Cordes almost 9 years ago
Updated by Helmut Hummel almost 9 years ago
- Project changed from 1716 to TYPO3 Core
- Category deleted (
OW-A07: Cross Site Scripting) - Is Regression set to No