Details
-
Bug
-
Resolution: Fixed
-
Critical
-
4.12.2
-
None
-
None
-
Informal
-
Security
Description
Select Templates allow to add HTML tags to control the rendering.
This is a security issue since users with write access may add unwanted tags.
Use PDAC-1462 to store templates with allowed HTML code as space properties.
The strict rendering is off per default for version 4 of the projectdoc Toolbox. It will be the default for version 5. Use the system property de.smartics.projectdoc.security.strictHtmlEncoding set to true to demand strict encoding.