View Issue Details

This bug affects 1 person(s).
 4
IDProjectCategoryView StatusLast Update
20069Bug reportsCentral participant databasepublic2025-04-29 13:31
ReporterDenisChenu Assigned To 
PrioritynoneSeverityminor 
Status newResolutionopen 
Product Version6.6.x 
Summary20069: Some attribute are not shown
Description

When using < or > etc ... in CPDB attribute value : It shown partially as HTML

Steps To Reproduce

Steps to reproduce

Create an attribute text-box
Create a user with attribute <script>alert('XSS')</script>
Create a user with attribute <strong>strong</strong>

Expected result

See encoded value in listing

Actual result

See not encoded and filtered value

TagsNo tags attached.
Attached Files
Bug heat4
Complete LimeSurvey version number (& build)6.13.0
I will donate to the project if issue is resolvedNo
Browsernot relevant
Database type & versionnot relevant
Server OS (if known)not relevant
Webserver software & version (if known)not relevant
PHP Versionnot relevant

Users monitoring this issue

There are no users monitoring this issue.

Activities

c_schmitz

c_schmitz

2025-04-29 13:30

administrator   ~82525

Hm.. I think this might be intended?

DenisChenu

DenisChenu

2025-04-29 13:31

developer   ~82526

Hm.. I think this might be intended?

When you edit : no HTML editor, just plain text. Then i really don't think it's inteded

Issue History

Date Modified Username Field Change
2025-04-22 12:03 DenisChenu New Issue
2025-04-22 12:03 DenisChenu File Added: Capture d’écran du 2025-04-22 12-02-53.png
2025-04-22 12:03 DenisChenu Steps to Reproduce Updated
2025-04-29 13:30 c_schmitz Note Added: 82525
2025-04-29 13:30 c_schmitz Bug heat 0 => 2
2025-04-29 13:31 DenisChenu Note Added: 82526
2025-04-29 13:31 DenisChenu Bug heat 2 => 4