-
Type: Bug
-
Status: Closed (View Workflow)
-
Priority: Major
-
Resolution: Fixed
-
Affects Version/s: 2.10 Larks
-
Fix Version/s: 2.12 Larks
-
Labels:None
-
Sprint:2.12 Larks
Precondition
- install Web Developer plugin for your browser
Steps to reproduce:
- Login and open Create Topic page
- Go to "Ending date" field.
- Convert the field to textarea using WebDeveloper plugin (Forms -> Convert Text Inputs to Textsreas)
- Type any sql-injection, for example: 1' OR '1'='1
- Press "Save" button
Actual result: Following error message appears:
Failed to convert property value of type java.lang.String to required type org.joda.time.DateTime for property topic.poll.endingDate; nested exception is java.lang.IllegalArgumentException: Invalid format: "1 OR 1=1" is malformed at " OR 1=1"
Expected result: user-friendly error message is shown, for ex.
EN: "Please, choose the correct date"
RU: "Пожалуйста, выберите корректную дату"