[jira] [Comment Edited] (OFBIZ-7150) Character encoding issue on field Question in Survey Questions List

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Comment Edited] (OFBIZ-7150) Character encoding issue on field Question in Survey Questions List

Nicolas Malin (Jira)

    [ https://issues.apache.org/jira/browse/OFBIZ-7150?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15314802#comment-15314802 ]

Jacques Le Roux edited comment on OFBIZ-7150 at 6/3/16 9:58 PM:
----------------------------------------------------------------

Hi Pranay,
As Deepak supposed, this is fine (in EditSurveyQuestions.ftl) as long as you don't enter something like
bq. <script>alert('XSS')</script>
in the question field. If you do and then get to ecommerce and purchase a gift carf you see !Image 005.png!

Sorry but another solution must be found.


was (Author: jacques.le.roux):
Hi Pranay,
As Deepak supposed, this is fine (in EditSurveyQuestions.ftl) as long as you don't get enter something like
bq. <script>alert('XSS')</script>
in the question field. If you then get to ecommerce and purchase a gift carf you see !Image 005.png!

Sorry but another solution must be found.

> Character encoding issue on field Question in Survey Questions List
> -------------------------------------------------------------------
>
>                 Key: OFBIZ-7150
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-7150
>             Project: OFBiz
>          Issue Type: Bug
>          Components: content
>    Affects Versions: Release Branch 14.12, Trunk, Release Branch 15.12
>            Reporter: Pranay Pandey
>            Assignee: Pranay Pandey
>            Priority: Minor
>         Attachments: Image 005.png, OFBIZ-7150-Screenshot.png, OFBIZ-7150.patch
>
>
> Character encoding issue found on field Question in Survey Questions List.
> Please refer attached screenshot for the same.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)