- Posts: 21
- Thank you received: 2
Ask the community, share ideas, and connect with other LimeSurvey users!
Depends on the attack vector. E.g EXIF comment field can contain malware code.DenisChenu wrote: I don't think you can have malware on image files,
Yes, OK : part of malware are inside comment.jelo wrote:
Depends on the attack vector. E.g EXIF comment field can contain malware code.DenisChenu wrote: I don't think you can have malware on image files,
blog.sucuri.net/2018/07/hiding-malware-i...ogleusercontent.html
I don't say it's perfect , but with XSS security to on (and not be a super-admin) : uploading lss are filtered for JS and other harmfull code (using htmlpurifier.org/ ).I don't see LimeSuvey able to secure all attack vectors (uploading LSS with malicious js code inside).
XSS security would be working in a world without workarounds. LimeSurvey without workarounds is what?DenisChenu wrote: but with XSS security to on
User who came on forum need very specific solution.jelo wrote:
XSS security would be working in a world without workarounds. LimeSurvey without workarounds is what?DenisChenu wrote: but with XSS security to on
People contacting you are already on LimeSurvey soil. Your customers can leave XSS on, cause they get a plugin installed I wonder if 95% of TPartners customers conduct surveys without any workaround.DenisChenu wrote: More than 95% of my survey is done without any workaround …
No for public part .jelo wrote: Your customers can leave XSS on, cause they get a plugin installed .