View Issue Details

IDProjectCategoryView StatusLast Update
4645Composrcore_webstandardspublic2021-04-26 15:24
ReporterChris Graham Assigned ToChris Graham  
PriorityhighSeverityminor 
Status resolvedResolutionfixed 
Product Version10.0.37 
Fixed in Version10.0.38 
Summary4645: Invalid HTML can crash validator
DescriptionI'm not completely clear on the reproduction conditions, but we got an automated error report of invalid HTML producing a crash (from someone probing Composr for security edge cases). Specifically a lone '&' that is not part of an entity. It may not be a common condition, as it may typically require this invalid HTML to come out of the WYSIWYG editor which is not possible.
TagsNo tags attached.
Attach Tags
Attached Files
Time estimation (hours)
Sponsorship open

Sponsor

Date Added Member Amount Sponsored

Activities

admin

2021-04-26 15:24

administrator   ~7080

Fixed in git commit cf1c2637e (https://gitlab.com/composr-foundation/composr/commit/cf1c2637e - link will become active once code pushed to GitLab)

A hotfix (a TAR of files to upload) has been uploaded to this issue. These files are made to the latest intra-version state (i.e. may roll in earlier fixes too if made to the same files) - so only upload files newer than what you have already. If there are files in a hot-fix that you don't have then they probably relate to addons that you don't have installed and should be skipped. Always take backups of files you are replacing or keep a copy of the manual installer for your version, and only apply fixes you need. These hotfixes are not necessarily reliable or well supported. Not sure how to extract TAR files to your Windows computer? Try 7-zip (http://www.7-zip.org/).

Issue History

Date Modified Username Field Change