Dropzone area message is not rendered through the Twig, which means that it is not automatically sanitized. I tried to exploit it, but it seems that any Javascript code injected into it won't fire.

I think that we should escape the text nonetheless.

Problem is mitigated by the fact that one needs administrative permission to potentially exploit it.

CommentFileSizeAuthor
#2 2854175_2.patch884 bytesslashrsm

Comments

slashrsm created an issue. See original summary.

slashrsm’s picture

Issue summary: View changes
Status: Active » Needs review
StatusFileSize
new884 bytes

  • Primsi committed 9e1f51b on 8.x-1.x authored by slashrsm
    Issue #2854175 by slashrsm: Properly sanitize user-defined dropzone...
primsi’s picture

Status: Needs review » Fixed

Committed, thanks.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.