[7.0] Important field not escaped (Messaging / Inbox / Record Name)

Bug #1276078 reported by Arnaud Pineux (OpenERP)
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Odoo Addons (MOVED TO GITHUB)
Fix Released
High
Unassigned

Bug Description

1) To reproduce:
- Change the name of the demo user to <script>alert('demo user')</script>
- Go on Messaging/ Inbox menu
- If there are message that concern "demo user" then you should have a popup showing "demo user"
2) Result observed:
The script is executed
3) Result expected:
The record name should be escaped or sanitized
4) Fedora/Chrome
5) Tested on 7.0 (on runbot)

Related branches

Changed in openobject-addons:
status: New → Confirmed
importance: Undecided → High
Revision history for this message
Martin Trigaux (OpenERP) (mat-openerp) wrote :

Fix merged in 7.0, thanks for the report

revno: 9807 [merge]
revision-id: <email address hidden>

Changed in openobject-addons:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.