plainblack.com
Username Password
search
Bookmark and Share
View All Tickets
Scratch variables for sort direction and key can break the CS  (#11510)
Issue

If form variables for sort direction and key are passed to the CS, they are set as scratch variables.  Scratch variables never die, and the CS never clears them out itself.

Someone in the world has a sort scratch variable set for dateSubmitted, and they are accessing the CMSMatrix and are not allowed to access the forums any longer.

Solution Summary
Comments
perlDreamer
0
4/5/2010 12:40 pm
Added a whitelist of allowed sort fields, userDefined1-5, title, lineage, revisionDate, creationDate, karmaRank and threadRank.

Fixed in 7.9.2 (6990f52)
Fixed in 7.8.16 (776f0c4)
Details
Ticket Status Resolved  
Rating0.0 
Submitted ByperlDreamer 
Date Submitted2010-03-31 
Assigned To unassigned  
Date Assigned2019-05-21 
Assigned By 
Severity Critical (mostly not working)  
What's the bug in? WebGUI Stable  
WebGUI / WRE Version 7.x  
URLuse/bugs/tracker/11510
Keywords
Collaboration System scratch variables woeful badness
Ticket History
4/5/2010
5:40 PM
Resolved perlDreamer
4/1/2010
12:31 AM
Ticket created perlDreamer
© 2019 Plain Black Corporation | All Rights Reserved