Uploaded image for project: 'Plugins'
  1. Plugins
  2. CONTRIB-6919

Capabilities with possible XSS risk should declare the RISK_XSS mask

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 3.3
    • Fix Version/s: 3.3
    • Component/s: Module: Questionnaire
    • Labels:
      None

      Description

      See the pull request at https://github.com/remotelearner/moodle-mod_questionnaire/pull/27

      In the db/access.php capabilities that allow the user to insert javascript should have their risk mask declare RISK_XSS for complete documentation.

      Update these capability declarations to declare this:

      mod/questionnaire:editquestions
      mod/questionnaire:manage

        Attachments

          Activity

            People

            Assignee:
            mchurch Mike Churchward
            Reporter:
            mchurch Mike Churchward
            Participants:
            Component watchers:
            Mike Churchward
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Fix Release Date:
              15/May/17