Template:XSS alert
Appearance
From mediawiki.org
Languages:
Warning: The code or configuration described here poses a major security risk.
Problem: Vulnerable to Cross-site scripting attacks, because it passes user input directly to the browser. This may lead to user accounts being hijacked, among other things.
Solution: strictly validate user input and/or apply escaping to all characters that have a special meaning in HTML
Site administrators: You are advised against using it until this security issue is resolved.
Problem: Vulnerable to Cross-site scripting attacks, because it passes user input directly to the browser. This may lead to user accounts being hijacked, among other things.
Solution: strictly validate user input and/or apply escaping to all characters that have a special meaning in HTML
Template documentation
- Description
- Adds an alert box describing a Cross-site scripting vulnerability in including Extension page. Also adds including page to Category:Extensions with XSS vulnerabilities
- If your extension was tagged with this template please read
- For extension developers and extension users: Cross-site scripting
- Specifically for extension developers: Security for developers
- Example
{{XSS alert|~~~~}}
- Creates
Warning: The code or configuration described here poses a major security risk.
Problem: Vulnerable to Cross-site scripting attacks, because it passes user input directly to the browser. This may lead to user accounts being hijacked, among other things. Duesentrieb ⇌ 13:43, 22 March 2007 (UTC)
Solution: strictly validate user input and/or apply escaping to all characters that have a special meaning in HTML Duesentrieb ⇌ 13:43, 22 March 2007 (UTC)
Site administrators: You are advised against using it until this security issue is resolved.
Problem: Vulnerable to Cross-site scripting attacks, because it passes user input directly to the browser. This may lead to user accounts being hijacked, among other things. Duesentrieb ⇌ 13:43, 22 March 2007 (UTC)
Solution: strictly validate user input and/or apply escaping to all characters that have a special meaning in HTML Duesentrieb ⇌ 13:43, 22 March 2007 (UTC)
Editors can experiment in this template’s sandbox (create | mirror) and testcases (create) pages.
Subpages of this template.
Subpages of this template.