Project

General

Profile

Actions

Bug #17641

closed

Markdown descriptions in directives and groups are evaluated, resulting in Javascript execution

Added by Nicolas CHARLES almost 4 years ago. Updated 9 months ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:

Description

We can use markdown for Directives and Groups description, to have more friendly description
However, it's possible to put script with this markdown, that gets executed when displaying the group or directive details (and also in change request list)

This ticket fixes the issue by using the showdown xss filter to prevent evaluation of javascript in markdown


Subtasks 1 (0 open1 closed)

Bug #17698: Tooltips in interface tree evaluate scripts ReleasedFrançois ARMANDActions
Actions

Also available in: Atom PDF