← Back to team overview

openerp-india team mailing list archive

[Bug 1276078] [NEW] [7.0] Important field not escaped (Messaging / Inbox / Record Name)

 

Public bug reported:

1) To reproduce:
- Change the name of the demo user to <script>alert('demo user')</script>
- Go on Messaging/ Inbox menu
- If there are message that concern "demo user" then you should have a popup showing "demo user"
2) Result observed:
The script is executed
3) Result expected:
The record name should be escaped or sanitized
4) Fedora/Chrome
5) Tested on 7.0 (on runbot)

** Affects: openobject-addons
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of OpenERP
Indian Team, which is subscribed to OpenERP Addons.
https://bugs.launchpad.net/bugs/1276078

Title:
  [7.0] Important field not escaped (Messaging / Inbox / Record Name)

Status in OpenERP Addons (modules):
  New

Bug description:
  1) To reproduce:
  - Change the name of the demo user to <script>alert('demo user')</script>
  - Go on Messaging/ Inbox menu
  - If there are message that concern "demo user" then you should have a popup showing "demo user"
  2) Result observed:
  The script is executed
  3) Result expected:
  The record name should be escaped or sanitized
  4) Fedora/Chrome
  5) Tested on 7.0 (on runbot)

To manage notifications about this bug go to:
https://bugs.launchpad.net/openobject-addons/+bug/1276078/+subscriptions


Follow ups

References