Details
-
Type: Bug
-
Status: Done/Fixed
-
Priority: Minor
-
Resolution: Fixed/Completed
-
Affects Version/s: 3.1.5
-
Fix Version/s: 3.2
-
Component/s: None
-
Labels:None
Description
Reported by Tim otten. We should do two things:
1. ensure we turn on smarty security in this mode to make the evaluation more secure
2. convert '
{' and '}' to
{ldelim}and
{rdelim}so that any potential commands embedded in the database are not interpreted as smarty commands