Uploaded image for project: 'JCommune'
  1. JCommune
  2. JC-157

It's possible to use such code <form action="http://yandex.ru"><input type="submit"></form> in user name/surname

    Details

      Description

      It's possible to input in First name/Last name fields during the registration or after registration in users profile, code such : <form action="http://yandex.ru"><input type="submit"></form>

        Attachments

          Activity

          Hide
          wedens Kirill Afonin added a comment -

          html escaping not implemented yet. you can also use XSS, CSRF

          Show
          wedens Kirill Afonin added a comment - html escaping not implemented yet. you can also use XSS, CSRF
          Hide
          odanee Olga Danieloff added a comment -

          verified

          Show
          odanee Olga Danieloff added a comment - verified

            People

            • Assignee:
              odanee Olga Danieloff
              Reporter:
              biomaks Erik Khalimov
            • Votes:
              0 Vote for this issue
              Watchers:
              Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Structure Helper Panel