Security concern with Free text fields not having some restrictions #11958
Tribunal33
started this conversation in
Proposals
Replies: 1 comment
-
|
See also: |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
While testing I have noticed that several free text form fields do not have a any input restrictions. Even in areas where there is going to be a max 25 character limit. This can lead to problems such as this bug #11769. As well, I briefly talked about setting the number of processed citations to 100 here : #11902. But even within these processed citations are multiple text fields that have no character limits on inputs. I propose a standard solution for limiting these fields to some maximum character restrictions before the Database throws errors.
If not then it opens up attacks for malicious users as outlined here : https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html#:~:text=When%20designing%20regular%20expression%2C%20be,Allow%20List%20Regular%20Expression%20Examples
Beta Was this translation helpful? Give feedback.
All reactions