Information Required J3 Issue ?
avatar Quy
Quy
3 May 2018

The Email this link to a friend form can be used to spam. There are no length restrictions to Sender and Subject fields. As a result, block of text/links can be inserted into the email subject/body with these two fields.

Possible solutions:

  • Remove subject field and use article's title instead
  • Limit length of Sender field
  • Remove links from these fields

Votes

# of Users Experiencing Issue
0/1
Average Importance Score
3.00

avatar Quy Quy - open - 3 May 2018
avatar joomla-cms-bot joomla-cms-bot - change - 3 May 2018
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 3 May 2018
avatar franz-wohlkoenig franz-wohlkoenig - change - 3 May 2018
Status New Discussion
avatar franz-wohlkoenig franz-wohlkoenig - change - 3 May 2018
Category com_mailto
avatar brianteeman brianteeman - change - 28 May 2018
Labels Added: J3 Issue
avatar brianteeman brianteeman - labeled - 28 May 2018
avatar brianteeman
brianteeman - comment - 23 Jul 2018

Personally I would remove this functionality completely from joomla

avatar zero-24
zero-24 - comment - 23 Jul 2018

As of 3.8.9 we have added captcha support so this is as save as the contact form. By that time the removal was suggested but never confirmed in the internal security tracker.

@wilsonge can you take a moment and take a decision for 4.0? We would also need to take care what happen on upgrades.

avatar Quy
Quy - comment - 8 Jun 2019

Pending PR #24025

avatar franz-wohlkoenig
franz-wohlkoenig - comment - 8 Jun 2019

If #24025 is merged this Issue get closed.

avatar franz-wohlkoenig franz-wohlkoenig - change - 8 Jun 2019
Labels Added: Information Required
avatar franz-wohlkoenig franz-wohlkoenig - labeled - 8 Jun 2019
avatar Quy Quy - change - 14 Jun 2019
Status Discussion Closed
Closed_Date 0000-00-00 00:00:00 2019-06-14 19:27:56
Closed_By Quy
avatar Quy Quy - close - 14 Jun 2019

Add a Comment

Login with GitHub to post a comment