? ? Pending

User tests: Successful: Unsuccessful:

avatar PhilETaylor
PhilETaylor
15 Jan 2021

Summary of Changes

[4] revert and improve #32013 to use htmlspecialchars on user supplied placeholders and use non html entity for the bullet to overcome the entity being destroyed by htmlspecialchars

Testing Instructions

Look at Joomla Global Configuration Database Password field - ensure placeholders are and not asterisks or badly formatted

Actual result BEFORE applying this Pull Request

Potential XSS on any non-core use of this field with a user supplied $hint and $lock set to no.

Expected result AFTER applying this Pull Request

In line with all other user supplied placeholders, htmlspecialchars is applied to prevent XSS injections.

Documentation Changes Required

None.

// @brianteeman

avatar PhilETaylor PhilETaylor - open - 15 Jan 2021
avatar PhilETaylor PhilETaylor - change - 15 Jan 2021
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 15 Jan 2021
Category Layout
avatar ceford ceford - test_item - 25 Jan 2021 - Tested successfully
avatar ceford
ceford - comment - 25 Jan 2021

I have tested this item successfully on 2fc4784

I see the bullets in the password field and the two changes to the layout file.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32044.

avatar PhilETaylor PhilETaylor - change - 25 Jan 2021
Labels Added: ?
ed0e1d7 25 Jan 2021 avatar PhilETaylor cs
40ddfee 25 Jan 2021 avatar PhilETaylor cs
avatar PhilETaylor
PhilETaylor - comment - 25 Jan 2021

Merged back 4.0-dev and fixed cs, and reverted back to bootstrap 5 version. Ready to test again.

avatar ceford ceford - test_item - 25 Jan 2021 - Tested successfully
avatar ceford
ceford - comment - 25 Jan 2021

I have tested this item successfully on 40ddfee


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32044.

avatar gostn gostn - test_item - 31 Jan 2021 - Tested successfully
avatar gostn
gostn - comment - 31 Jan 2021

I have tested this item successfully on 40ddfee


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32044.

avatar Quy Quy - change - 31 Jan 2021
Status Pending Ready to Commit
avatar Quy
Quy - comment - 31 Jan 2021

RTC


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32044.

avatar infograf768 infograf768 - change - 8 Feb 2021
Status Ready to Commit Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2021-02-08 08:42:46
Closed_By infograf768
Labels Added: ?
avatar infograf768 infograf768 - close - 8 Feb 2021
avatar infograf768 infograf768 - merge - 8 Feb 2021
avatar infograf768
infograf768 - comment - 8 Feb 2021

Tks

Add a Comment

Login with GitHub to post a comment