VirtueMart Forum

VirtueMart 2 + 3 + 4 => Virtuemart Development and bug reports => Topic started by: balai on October 27, 2015, 13:02:20 PM

Title: Custom field inputs non-sanitized
Post by: balai on October 27, 2015, 13:02:20 PM
I tried entering some scripts or html as values in string custom fields and they are entered normally.

I suppose that since they are simple strings such characters should be cleaned

Also noticed that they are displayed in the front-end without being cleaned or encoded either
Title: Re: Custom field inputs non-sanitized
Post by: Milbo on October 27, 2015, 21:01:29 PM
Because you are admin. Check the same as non admin, or take a look in the ACL to get the difference.