Jump to content

Blacklisted words in CMS


Recommended Posts

Well,

This is the first time I encounter such a bizarre security protection logic.
I must use the word "revoke" in one of my CMS documents, but the system wont let me insert it.

Is there a way to safely overcome this?
I mean, I tried inputting revoke in the HTML editor, but the page converts it back to "revoke" before saving, and does not save it.

I feel completely stupid telling my legal team that they cannot use a perfectly legitimate english word, because it is a security risk.....

I saw some information here an there on the forums, that looks related but was in French.

Any help is appreciated.

Link to comment
Share on other sites

Thanks San Diego,

Yes, I saw the blacklist in classes/DB.php
And what if the word "the" was a special database word?

It does not change the fact that there must be a better way to prevent security breaches than to just prevent english words...

I dont want to remove this word from the list, as I do not know what risks it may pose, but I definitely hope that someone can post a solution here.
This is a legal document, so "r e v o k e" is not going to cut it.

:)

Link to comment
Share on other sites

PrestaShop 1.2 won't have this blacklist anymore, if you can wait for its release (don't ask when :roll: ).

Else, you'll have to write "revoke" in another way (for example rev0ke, with a zero) or remove it from the list.

If you want to add it on a CMS page, you may try to write it like this :
revoke
This HTML markup will be stored in the DB but won't be displayed.
Hack found here.

Link to comment
Share on other sites

×
×
  • Create New...