View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 20316 | Feature requests | Other | public | 2025-10-22 11:24 | 2026-03-06 16:12 |
| Reporter | DenisChenu | Assigned To | gabrieljenik | ||
| Priority | none | Severity | feature | ||
| Status | ready for code review | Resolution | open | ||
| Summary | 20316: XSS for superadmin too | ||||
| Description |
| ||||
| Additional Information | In my opinion : only config.php updfate. Can not be updated by GUI
| ||||
| Tags | No tags attached. | ||||
| Bug heat | 6 | ||||
| Story point estimate | 0 | ||||
| Users affected % | 10 | ||||
|
@ tibor.pacalat : same than some other feature request. The alternative is to create a plugin, but
|
|
|
From Carsten: |
|
|
From global settings to User Permission ? BUT we still have the same issue for superadmin ! |
|
|
Better name for option : |
|
This is another issue. Here the desired behavior is Nobody can add script tag even superadmin. Since superadmin have all permission : adding a new permission didn'(t fix the issue. Proposition :
|
|
|
OK, |
|
|
Plugin and create a PR to have the plugin integrated in core :) |
|
|
Not set : use GUI |
|
|
Did we need I think we can set (maybe) when install ? |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2025-10-22 11:24 | DenisChenu | New Issue | |
| 2025-10-22 11:27 | DenisChenu | Note Added: 83636 | |
| 2025-10-22 11:27 | DenisChenu | Bug heat | 0 => 2 |
| 2025-10-22 11:27 | DenisChenu | Additional Information Updated | |
| 2025-10-22 16:33 | tibor.pacalat | Note Added: 83650 | |
| 2025-10-22 16:33 | tibor.pacalat | Bug heat | 2 => 4 |
| 2025-10-22 16:35 | DenisChenu | Note Added: 83651 | |
| 2025-10-27 09:19 | DenisChenu | Note Added: 83673 | |
| 2025-11-28 17:43 | DenisChenu | Note Added: 83966 | |
| 2025-11-28 18:46 | DenisChenu | Note Added: 83967 | |
| 2025-12-01 14:23 | DenisChenu | Note Added: 83968 | |
| 2025-12-24 13:43 | admin097 | Note Added: 84052 | |
| 2025-12-24 13:43 | admin097 | Bug heat | 4 => 6 |
| 2026-01-22 10:30 | DenisChenu | Assigned To | => DenisChenu |
| 2026-01-22 10:30 | DenisChenu | Status | new => assigned |
| 2026-03-06 09:01 | DenisChenu | Note Added: 84405 | |
| 2026-03-06 09:03 | DenisChenu | Note Added: 84406 | |
| 2026-03-06 09:04 | DenisChenu | Note Edited: 84406 | |
| 2026-03-06 16:12 | DenisChenu | Assigned To | DenisChenu => gabrieljenik |
| 2026-03-06 16:12 | DenisChenu | Status | assigned => ready for code review |
| 2026-03-06 16:12 | DenisChenu | Note Added: 84411 |