Skip to content

WAF deteting Unicode character bypass #678

@CIMEOS

Description

@CIMEOS

Hi,
we recently configured a WAF on our servers and it is blocking any request containing unicode characters with the message : Possible Unicode character bypass detected.

Example of blocked request content where "\u00e9" should be "é" :
"info\":1,\"new\":1,\"dragdrop\":1,\"sort\":1,\"hide\":1,\"delete\":1,\"localize\":1},\"levelLinksPosition\":\"top\",\"newRecordLinkTitle\":\"Cr\\u00e9er un bouton\",\"showAllLocalizationLi"

From what we saw, errors can be triggered while saving mask configuration or in content editing (BE) like adding an item in a section field type.

Tested on typo3v12 and typo3v13

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions