Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory fusiondirectory
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 33
    • Issues 33
    • List
    • Boards
    • Service Desk
    • Milestones
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Terraform modules
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectoryfusiondirectory
  • Issues
  • #5868
Closed
Open
Issue created Aug 13, 2018 by bmortier@bmortierMaintainer

HTML is not escaped in departments descriptions

Description

If you put HTML in a department description field, it gets rendered in the department list.

FusionDirectory Version

1.2

Steps to Reproduce

  1. Create a department
  2. Put <b>FooBar</b><br> is the name. in the description
  3. Look at the department list

Expected behavior:

HTML is escaped

Actual behavior:

HTML is rendered

Additional Information

Department tree in base field is affected as well. Other columns should be checked as well for most objects, and we should make sure 1.4 management class does not have the problem.

Edited Aug 13, 2018 by bmortier
Assignee
Assign to
Time tracking