-
Notifications
You must be signed in to change notification settings - Fork 21
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Possible XSS vulnerability? #33
Comments
Hi David. nick [at] nick-dunn [dot] co.uk will reach me. Thanks :-) |
@davidhund has this been resolved back then? |
Thanks David. Nick is long gone from the Symphony CMS community. ElasticSearch is no option for my projects, so I’m trying to keep this one alive :) Just wanted to see if there was anything done about this back then. |
@animaux Try to wrap the values in cdata section. The xml failing to load is kind of normal when you input thing into it that is not valid. |
I implemented Search Index in a site recently and already notice XSS attacks ("tries", I guess) popping up in the logs.
While I don't think there are serious issues one keyword does result in a XSLT error:
loadXML(): attributes construct error in Entity, line: 275
loadXML(): Couldn't find end of Start Tag keyword line 275 in Entity, line: 275
I am hesitant to post the triggering keyword but could mail you more details personally?
The text was updated successfully, but these errors were encountered: