Openbravo Issue Tracking System - Openbravo ERP |
View Issue Details |
|
ID | Project | Category | View Status | Date Submitted | Last Update |
0033231 | Openbravo ERP | A. Platform | public | 2016-06-13 13:05 | 2018-02-22 18:18 |
|
Reporter | caristu | |
Assigned To | caristu | |
Priority | high | Severity | minor | Reproducibility | always |
Status | closed | Resolution | fixed | |
Platform | | OS | 5 | OS Version | |
Product Version | | |
Target Version | | Fixed in Version | 3.0PR16Q3 | |
Merge Request Status | |
Review Assigned To | alostale |
OBNetwork customer | |
Web browser | |
Modules | Core |
Support ticket | |
Regression level | |
Regression date | |
Regression introduced in release | |
Regression introduced by commit | |
Triggers an Emergency Pack | No |
|
Summary | 0033231: Prevent usage of filter clause as an URL parameter |
Description | Currently it is possible to override the default filtering of a standard window, by passing a filter clause as an URL parameter.
This affects to the security, as the parameter can be used for injection. |
Steps To Reproduce | In description |
Proposed Solution | |
Additional Information | |
Tags | No tags attached. |
Relationships | related to | feature request | 0032610 | 3.0PR16Q3 | closed | NaroaIriarte | standard datasources shouldn't accept where parameter by default | related to | feature request | 0018586 | 3.0MP5 | closed | mtaal | Extend grid linking to include filter settings |
|
Attached Files | |
|
Issue History |
Date Modified | Username | Field | Change |
2016-06-13 13:05 | caristu | New Issue | |
2016-06-13 13:05 | caristu | Assigned To | => caristu |
2016-06-13 13:05 | caristu | Modules | => Core |
2016-06-13 13:05 | caristu | Triggers an Emergency Pack | => No |
2016-06-13 13:05 | caristu | Relationship added | related to 0032610 |
2016-06-13 13:05 | caristu | Status | new => scheduled |
2016-06-13 13:21 | caristu | Relationship added | related to 0018586 |
2016-06-13 19:42 | hgbot | Checkin | |
2016-06-13 19:42 | hgbot | Note Added: 0087215 | |
2016-06-13 19:42 | hgbot | Status | scheduled => resolved |
2016-06-13 19:42 | hgbot | Resolution | open => fixed |
2016-06-13 19:42 | hgbot | Fixed in SCM revision | => http://code.openbravo.com/erp/devel/pi/rev/9023f7c3e56ceaf3f6b6b9743a56db342623da5d [^] |
2016-06-13 19:46 | caristu | Review Assigned To | => alostale |
2016-06-13 19:46 | caristu | Issue Monitored: alostale | |
2016-06-17 19:38 | hudsonbot | Checkin | |
2016-06-17 19:38 | hudsonbot | Note Added: 0087610 | |
2016-06-20 13:09 | alostale | Note Added: 0087670 | |
2016-06-20 13:09 | alostale | Status | resolved => closed |
2016-06-20 13:09 | alostale | Fixed in Version | => 3.0PR16Q3 |
2018-01-30 17:29 | hgbot | Checkin | |
2018-01-30 17:29 | hgbot | Note Added: 0102070 | |
2018-01-30 17:58 | caristu | Note Deleted: 0102070 | |
2018-02-22 18:18 | hudsonbot | Checkin | |
2018-02-22 18:18 | hudsonbot | Note Added: 0102698 | |