WYSIWYG Editor Security Question (Preventing Malicious Input)

I use jWYSIWYG in the form that I create these messages in the database and wondered how you can prevent an attacker from trying to enter code into a frame?

Does the parenthesis editor (which I usually remove during the mail process) be needed to display styles?

+3
source share
3 answers

I came across similar situations and I started using HTMLPurifier on my PHP server, which will prevent any attack vector that I can think of. It is easy to install and allows you to rename elements and attributes. It also prevents XSS attacks that may still exist when using htmlentities.

+1
source

If the editor allows arbitrary HTML, you are fighting a lost battle, as users can simply use the editor to create their own malicious content.

, ( , stackoverflow), HTML, .

, , , .

+2

, , , , . htmlentites , , . script, Kohana php input XSS:

http://svn.bitflux.ch/repos/public/popoon/trunk/classes/externalinput.php

+2
source

Source: https://habr.com/ru/post/1750169/


All Articles