openerp-india team mailing list archive
-
openerp-india team
-
Mailing list archive
-
Message #27208
[Bug 1276078] [NEW] [7.0] Important field not escaped (Messaging / Inbox / Record Name)
Public bug reported:
1) To reproduce:
- Change the name of the demo user to <script>alert('demo user')</script>
- Go on Messaging/ Inbox menu
- If there are message that concern "demo user" then you should have a popup showing "demo user"
2) Result observed:
The script is executed
3) Result expected:
The record name should be escaped or sanitized
4) Fedora/Chrome
5) Tested on 7.0 (on runbot)
** Affects: openobject-addons
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of OpenERP
Indian Team, which is subscribed to OpenERP Addons.
https://bugs.launchpad.net/bugs/1276078
Title:
[7.0] Important field not escaped (Messaging / Inbox / Record Name)
Status in OpenERP Addons (modules):
New
Bug description:
1) To reproduce:
- Change the name of the demo user to <script>alert('demo user')</script>
- Go on Messaging/ Inbox menu
- If there are message that concern "demo user" then you should have a popup showing "demo user"
2) Result observed:
The script is executed
3) Result expected:
The record name should be escaped or sanitized
4) Fedora/Chrome
5) Tested on 7.0 (on runbot)
To manage notifications about this bug go to:
https://bugs.launchpad.net/openobject-addons/+bug/1276078/+subscriptions
Follow ups
References