Project

General

Profile

Actions

Bug #11765

closed

Invalid HTML encoding in modal Notices window

Added by Viktor Gurov almost 3 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Viktor Gurov
Category:
Notifications
Target version:
Start date:
04/01/2021
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
21.05
Release Notes:
Default
Affected Version:
2.5.0
Affected Architecture:

Description

In some cases it shows "&lt;head&gt" instead of "<head>":

https://acb.netgate.com/save (&amp;lt;html&amp;gt;
&amp;lt;head&amp;gt;&amp;lt;title&amp;gt;500 Internal Server Error&amp;lt;/title&amp;gt;&amp;lt;/head&amp;gt;
&amp;lt;body&amp;gt;
&amp;lt;center&amp;gt;&amp;lt;h1&amp;gt;500 Internal Server Error&amp;lt;/h1&amp;gt;&amp;lt;/center&amp;gt;
&amp;lt;hr&amp;gt;&amp;lt;center&amp;gt;nginx/1.16.0&amp;lt;/center&amp;gt;
&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;


Files

Actions #2

Updated by Jim Pingle almost 3 years ago

  • Status changed from New to Pull Request Review
  • Target version set to CE-Next
Actions #3

Updated by Jim Pingle almost 3 years ago

  • Status changed from Pull Request Review to Feedback
  • Target version changed from CE-Next to 2.6.0

PR was merged yesterday.

Actions #4

Updated by Jim Pingle almost 3 years ago

  • Plus Target Version set to 21.05
Actions #5

Updated by Jim Pingle almost 3 years ago

Already in 21.05 branch.

Actions #6

Updated by Jim Pingle almost 3 years ago

  • Target version changed from 2.6.0 to 2.5.2
Actions #7

Updated by Jim Pingle almost 3 years ago

  • Status changed from Feedback to Closed
  • Assignee set to Viktor Gurov
  • % Done changed from 0 to 100

Since the bug causing the original notice was random and hard to reproduce, and also has been fixed, it's not viable to test the exact original scenario.

It does appear to be working correctly now with a similarly crafted manual notice, though.

Actions

Also available in: Atom PDF