← Back to team overview

openerp-india team mailing list archive

[Bug 1276078] Re: [7.0] Important field not escaped (Messaging / Inbox / Record Name)

 

Fix merged in 7.0, thanks for the report

revno: 9807 [merge]
revision-id: mat@xxxxxxxxxxx-20140204141913-e5hcaml53woumlgs


** Changed in: openobject-addons
       Status: Confirmed => Fix Released

-- 
You received this bug notification because you are a member of OpenERP
Indian Team, which is subscribed to OpenERP Addons.
https://bugs.launchpad.net/bugs/1276078

Title:
  [7.0] Important field not escaped (Messaging / Inbox / Record Name)

Status in OpenERP Addons (modules):
  Fix Released

Bug description:
  1) To reproduce:
  - Change the name of the demo user to <script>alert('demo user')</script>
  - Go on Messaging/ Inbox menu
  - If there are message that concern "demo user" then you should have a popup showing "demo user"
  2) Result observed:
  The script is executed
  3) Result expected:
  The record name should be escaped or sanitized
  4) Fedora/Chrome
  5) Tested on 7.0 (on runbot)

To manage notifications about this bug go to:
https://bugs.launchpad.net/openobject-addons/+bug/1276078/+subscriptions


References