How to block execute script code #4517

jintaeson ·

We found that scripts are executable for all input fields.
Can I block that feature?

  1. Trigger build.
  2. Move build overview > Edit Description > "" > save
  3. Refresh page.
  4. "Alert XSS"
robinshen ADMIN ·

To turn it off, make sure to disable "Script Allowed" in all assigned groups. Nevertheless, adminsitrator can always run scripts.

jintaeson ·

It's basically disabled.
QB version : 11.0.33

  1. Move build overview > Edit Description > select "source" > input "<script>alert("XSS")" > save
  2. Alert "XSS"
robinshen ADMIN ·

Applications like QB should be used in a trust environment, and I think such issue is tolerable. Even if this is disabled, you still can not prevent users from running arbitrary logic as long as they are allowed to create configurations, as they can checkout from any desired source.