Script Injection in field collection

Created on 13 February 2019, over 5 years ago
Updated 22 August 2023, 10 months ago

I have created one filed collection with two fields
1-text 2-image with title when i inserted

alert("hacked")

into text , image title then its inserted with out any message into database. It should not be inserted or skip java script. How to avoid it

📌 Task
Status

Postponed: needs info

Component

Code

Created by

🇮🇳India fawwad.drupal

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • First commit to issue fork.
  • Assigned to viren18febS
  • 🇮🇳India viren18febS

    Checking the issue!

  • Issue was unassigned.
  • Status changed to Postponed: needs info 10 months ago
  • 🇮🇳India viren18febS

    HI fawwad,

    I have setup the field collection with two fields as you mentioned. I didn't getting any alert when insert the data. it's working fine for me. can you please elaborate the issue little more about what you get or what you want.

Production build 0.69.0 2024