openerp-india team mailing list archive
-
openerp-india team
-
Mailing list archive
-
Message #27211
[Bug 1276078] Re: [7.0] Important field not escaped (Messaging / Inbox / Record Name)
Fix merged in 7.0, thanks for the report
revno: 9807 [merge]
revision-id: mat@xxxxxxxxxxx-20140204141913-e5hcaml53woumlgs
** Changed in: openobject-addons
Status: Confirmed => Fix Released
--
You received this bug notification because you are a member of OpenERP
Indian Team, which is subscribed to OpenERP Addons.
https://bugs.launchpad.net/bugs/1276078
Title:
[7.0] Important field not escaped (Messaging / Inbox / Record Name)
Status in OpenERP Addons (modules):
Fix Released
Bug description:
1) To reproduce:
- Change the name of the demo user to <script>alert('demo user')</script>
- Go on Messaging/ Inbox menu
- If there are message that concern "demo user" then you should have a popup showing "demo user"
2) Result observed:
The script is executed
3) Result expected:
The record name should be escaped or sanitized
4) Fedora/Chrome
5) Tested on 7.0 (on runbot)
To manage notifications about this bug go to:
https://bugs.launchpad.net/openobject-addons/+bug/1276078/+subscriptions
References