View Issue Details

This bug affects 1 person(s).
 0
IDProjectCategoryView StatusLast Update
20069Bug reportsCentral participant databasepublic2025-04-22 12:03
ReporterDenisChenu Assigned To 
PrioritynoneSeverityminor 
Status newResolutionopen 
Product Version6.6.x 
Summary20069: Some attribute are not shown
Description

When using < or > etc ... in CPDB attribute value : It shown partially as HTML

Steps To Reproduce

Steps to reproduce

Create an attribute text-box
Create a user with attribute <script>alert('XSS')</script>
Create a user with attribute <strong>strong</strong>

Expected result

See encoded value in listing

Actual result

See not encoded and filtered value

TagsNo tags attached.
Attached Files
Bug heat0
Complete LimeSurvey version number (& build)6.13.0
I will donate to the project if issue is resolvedNo
Browsernot relevant
Database type & versionnot relevant
Server OS (if known)not relevant
Webserver software & version (if known)not relevant
PHP Versionnot relevant

Users monitoring this issue

There are no users monitoring this issue.

Activities

Issue History

Date Modified Username Field Change
2025-04-22 12:03 DenisChenu New Issue
2025-04-22 12:03 DenisChenu File Added: Capture d’écran du 2025-04-22 12-02-53.png
2025-04-22 12:03 DenisChenu Steps to Reproduce Updated