finetunedltd
Forum Replies Created
-
Forum: Plugins
In reply to: [Nested Pages] Cross Site Scripting (XSS) vulnerabilityYes it’s been more than two weeks now…!
yes, I have this issue on multiple sites
If you don’t explicitly add the email in the from field, the administrator email is inserted in its place.
The tooltip instructions for the from field: ‘Enter the name and/or email…’ suggest that the email is not required but the FORMAT part of the tooltip shows that it is required.
We had various end users who weren’t reading the tooltips fully and didn’t add the addresses where they had added names.
Defaulting to the administrator email makes sense but it would be good to validate the field contents via regex or similar?
hi Kristineds, I didn’t get this resolved. I’m still looking into it.
- This reply was modified 4 years, 1 month ago by finetunedltd.
Resolved too early, something weird is going on.
- This reply was modified 4 years, 1 month ago by finetunedltd.
form actions email – screenshot
- This reply was modified 4 years, 1 month ago by finetunedltd.