Skip to content

Conversation

@metamorfosec
Copy link

Hello..,
This is a pull request for issue #29 .

@atutor
Copy link
Owner

atutor commented Sep 22, 2018

There are some new problems with the content editor and rendered content contain page templates. When a page template is added the reorder buttons and a rouge X gets rendered when the content is displayed. The reorder button should only appear in the Page Template preview in the content editor.

content_screen

Can any of the HTML Purifier files be eliminated. There seems to be a lot of files that are not required. Also things like the form_demo.php in the crsf folder should be cleaned out.

I have not done a thorough code review. This pull request should be broken down into smaller more manageable chunks. And, a little more description provided with each.

As it is I can't merge this pull request.

metamorfosec and others added 21 commits September 23, 2018 09:26
We use TABLE_PREFIX to prevent error "Table ac_tests_questions doesn't exist" when editing or deleting created tests
We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent Reflected XSS for p parameter
We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent XSS for vulnerable or suspected parameters
We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent XSS for vulnerable or suspected parameters
We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent XSS for vulnerable or suspected parameters
We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent Reflected XSS for title parameter
We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent Reflected XSS for _cid parameter
1. We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent XSS for vulnerable or suspected parameters
2. If CSRF_Token is not valid and not recent, then make values from user unchangeable by CRSF Payload
We depend on htmlspecialchars, trim, stripslashes, and strip_tags to prevent XSS for vulnerable or suspected parameters
@metamorfosec
Copy link
Author

Hello..,
Thanks for fast response.
I have updated the files as your suggestion and the issue above should be fixed now.
However, I still have faced some warning messages as in original work also behaves like that.
I will provide the updates with more descriptive in smaller more manageable chunks as your suggestion.
Regards.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants