Security audit logviewer is not escaping tags

Description

One can add say a system property with a value <script>something<script>. It will show as a text on the System Property page. But in the Security audit log viewer this script will run. More than this, Security audit log viewer will not show previous entries if the one with the script is in the current showing range. Which could be a problem in the production environment, as you can't fix it by deleting the faulty system property. Audit entry will stay there unless one deletes it in the database.

Environment

None

Attachments

1

Activity

Show:

Tom Evans 
May 4, 2013 at 8:15 AM

Modified and applied patch; performed light testing via admin console. Presumed fixed.

Tom Evans 
May 4, 2013 at 7:59 AM

Patch under review (courtesy Peter Johnson).

Fixed

Details

Assignee

Reporter

Ignite Forum URL

Components

Fix versions

Affects versions

Priority

Created November 27, 2012 at 3:08 PM
Updated October 28, 2020 at 1:26 PM
Resolved May 4, 2013 at 8:15 AM