View Issue Details

This issue affects 1 person(s).
 254
IDProjectCategoryView StatusLast Update
14735Bug reportsSecuritypublic2019-04-04 07:55
Reporterbewi Assigned ToDenisChenu  
PrioritynoneSeverityminor 
Status closedResolutionno change required 
Product Version3.17.x 
Summary14735: not every admin should be allowed to edit all fields in source mode
Description

for RTE fields it is possible to switch to source mode. In this mode an admin can insert any HTML code. That could be an XSS, which everyone doing the survey (as preview or live) will execute.
the right to switch to source mode should be restrictable to selected admins.

TagsNo tags attached.
Bug heat254
Complete LimeSurvey version number (& build)3.17.0
I will donate to the project if issue is resolvedNo
Browser
Database type & version*
Server OS (if known)
Webserver software & version (if known)
PHP Version*

Users monitoring this issue

There are no users monitoring this issue.

Activities

DenisChenu

DenisChenu

2019-04-04 07:52

developer   ~51331

Only super admin have this right (by default). filterxsshtml https://manual.limesurvey.org/Optional_settings#Security and https://manual.limesurvey.org/Global_settings#Security

Source still can be edited , but when saved script are removed.

I close this one, if you want some improvments here : please open a feature request (for example : filterxsshtml for super admin too).

bewi

bewi

2019-04-04 07:55

reporter   ~51332

I should work as a normal admin more often ;)

Issue History

Date Modified Username Field Change
2019-04-04 07:38 bewi New Issue
2019-04-04 07:52 DenisChenu Assigned To => DenisChenu
2019-04-04 07:52 DenisChenu Status new => closed
2019-04-04 07:52 DenisChenu Resolution open => no change required
2019-04-04 07:52 DenisChenu Note Added: 51331
2019-04-04 07:55 bewi Note Added: 51332