Input from ajax form is not validated and there is no check wether input actually comes from ajax form. Ths is a potential security hazard.
Input from ajax form is not validated and there is no check wether input actually comes from ajax form. Ths is a potential security hazard.
Comments
Comment #1
alex_b commentedI don't know to what extent the menu system filters input - I guess there is some level of protection:
I just tried to inject javascript and php code with the ajax form, it doesn't get interpreted.
Comment #2
pomliane commentedThis version of Taxonomy User is not supported anymore. The issue is closed for this reason.
Please upgrade to a supported version and feel free to reopen the issue on the new version if applicable.
This issue has been automagically closed by a script.