[Tickets #13724] Re: STYLE tag stripped after send message

noreply at bugs.horde.org noreply at bugs.horde.org
Thu Nov 27 02:16:16 UTC 2014


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: https://bugs.horde.org/ticket/13724
------------------------------------------------------------------------------
  Ticket             | 13724
  Updated By         | Michael Slusarz <slusarz at horde.org>
  Summary            | STYLE tag stripped after send message
  Queue              | IMP
  Version            | 6.2.3
  Type               | Bug
-State              | Unconfirmed
+State              | Not A Bug
  Priority           | 2. Medium
  Milestone          |
  Patch              |
  Owners             |
------------------------------------------------------------------------------


Michael Slusarz <slusarz at horde.org> (2014-11-26 19:16) wrote:

This is the correct behavior.  Not only are STYLE tags are a potential  
XSS hazard, but they allow a user to circumvent attachment limits.





More information about the bugs mailing list