Skip to content

Filter tags (keywords) values in items.#4457

Merged
nilsteampassnet merged 1 commit intonilsteampassnet:masterfrom
corentin-soriano:xss_tags
Nov 14, 2024
Merged

Filter tags (keywords) values in items.#4457
nilsteampassnet merged 1 commit intonilsteampassnet:masterfrom
corentin-soriano:xss_tags

Conversation

@corentin-soriano
Copy link
Contributor

@corentin-soriano corentin-soriano commented Nov 12, 2024

Filter saved tags data with htmlspecialchars.
Remove double encoding in the edit form.
Clean database from a potential XSS payload present in the tags table during upgrade process.

@corentin-soriano corentin-soriano marked this pull request as ready for review November 12, 2024 14:54
@nilsteampassnet nilsteampassnet merged commit c94a524 into nilsteampassnet:master Nov 14, 2024
@corentin-soriano corentin-soriano deleted the xss_tags branch November 22, 2024 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants