ParamQuery Grid
Welcome,
Guest
. Please
login
or
register
.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Home
Help
Search
Login
Register
ParamQuery grid support forum
»
General Category
»
Help for ParamQuery Grid (free version)
»
How to prevent Cross-site Scripting(Xss) when input data
« previous
next »
Print
Pages: [
1
]
Author
Topic: How to prevent Cross-site Scripting(Xss) when input data (Read 2309 times)
Yiiiiii
Newbie
Posts: 2
How to prevent Cross-site Scripting(Xss) when input data
«
on:
March 05, 2019, 09:42:49 am »
I'm trying to edit cell data with text "<script>alert('something')</script>" but it seem possible .
Have any attribute of pqGrid to prevent XSS?
Logged
paramvir
Administrator
Hero Member
Posts: 6310
Re: How to prevent Cross-site Scripting(Xss) when input data
«
Reply #1 on:
March 19, 2019, 01:03:30 pm »
Free version doesn't have inbuilt support to prevent XSS,
you may add this manually in the column renderers.
Code:
[Select]
return val
.replace(/&/g, "&")
.replace(/<(\S)/g, "<$1")
Logged
Print
Pages: [
1
]
« previous
next »
ParamQuery grid support forum
»
General Category
»
Help for ParamQuery Grid (free version)
»
How to prevent Cross-site Scripting(Xss) when input data