Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-6439

Sanitize tokens from smarty statements when templates are evaluated with civicrm tokens and smarty tokens

    Details

    • Type: Bug
    • Status: Done/Fixed
    • Priority: Minor
    • Resolution: Fixed/Completed
    • Affects Version/s: 3.1.5
    • Fix Version/s: 3.2
    • Component/s: None
    • Labels:
      None

      Description

      Reported by Tim otten. We should do two things:

      1. ensure we turn on smarty security in this mode to make the evaluation more secure

      2. convert '

      {' and '}

      ' to

      {ldelim}

      and

      {rdelim}

      so that any potential commands embedded in the database are not interpreted as smarty commands

        Attachments

          Activity

            People

            • Assignee:
              lobo Donald A. Lobo
              Reporter:
              lobo Donald A. Lobo
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: