We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 23525
    • 7 Posts
    Running 0.9.6.2 version here, and I noticed that HTML tags are allowed and not escaped in site_content’s pagetitle property (and other document properties.) This could lead to security issues if someone manages to insert some XSS code in a document’s properties. This also doesn’t comply with W3 standard, especially for the <title> tag.

    Of course this only applies with the output is sensitive to these tags (HTML, XML, etc...) Is there any type of escaping for HTML output that can be enforced? undecided
      • 34127
      • 135 Posts
      You could check out HTML Purifier, which seems to do exactly what you need (prevents XSS, makes sure your code is standards compliant). There’s a MODx plugin for it too (about halfway down that page) which is pretty easy to install. smiley
        • 20413
        • 2,877 Posts
          @hawproductions | http://mrhaw.com/

          Infograph: MODX Advanced Install in 7 steps:
          http://forums.modx.com/thread/96954/infograph-modx-advanced-install-in-7-steps

          Recap: Portland, OR (PDX) MODX CMS Meetup, Oct 6, 2015. US Bancorp Tower
          http://mrhaw.com/modx_portland_oregon_pdx_modx_cms_meetup_oct_2015_us_bancorp_tower
          • 33372
          • 1,611 Posts
          You’re talking about values submitted from within the Manager, right? I don’t think there’s any need to sanitize tags from those fields, since you must be logged in to enter data there. Also consider that not everyone uses those fields in the same way that you do (for example, I often use pagetitle for things other than the <title> tag and when I use introtext as a meta description I strip tags from it in my meta tags snippet (so I can have tags in there for ditto pages and search results).

          If you’re really worried about this, you can always sanitize the values before outputting them to your pages.
            "Things are not what they appear to be; nor are they otherwise." - Buddha

            "Well, gee, Buddha - that wasn&#39;t very helpful..." - ZAP

            Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
            • 10487 MODX Staff
            • 1,535 Posts
            If you’re really worried about this, you can always sanitize the values before outputting them to your pages.
            Agreed, if you want to sanitize the values then you could use a plugin (on saving the ’document edit’ form via the manager) or use a snippet in the frontend to do that.
              Garry Nutting
              Senior Developer
              MODX, LLC

              Email: [email protected]
              Twitter: @garryn
              Web: modx.com