Welcome to the LimeSurvey Community Forum

Ask the community, share ideas, and connect with other LimeSurvey users!

Using html entities such as greater than or less than <> not parsing as text

  • holch
  • holch's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 3 weeks ago #243036 by holch
XSS is not activated. Did you look at my screenshots and what is happening there? There is definitely something wrong.

The > that I put is showing in the question, the "<" doesn't (but is in the text, thus hasn't been filtered, because the XSS is not on, I am also Superadmin)

I answer at the LimeSurvey forum in my spare time, I'm not a LimeSurvey GmbH employee.
No support via private message.

Please Log in to join the conversation.

  • DenisChenu
  • DenisChenu's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 3 weeks ago - 11 months 3 weeks ago #243059 by DenisChenu

XSS is not activated. Did you look at my screenshots and what is happening there? There is definitely something wrong.

The > that I put is showing in the question, the "<" doesn't (but is in the text, thus hasn't been filtered, because the XSS is not on, I am also Superadmin)

 
yes : because XSS is not activated for you : < is not shown

The HTML are this one

<option>Choice 1 <</option>

I think you can play (as super admin) to put

Choice 1 </option> <option>Choice 2

in the same answer … and see something strange …

PS : i think we need XSS filtering for superadmin too … (by options)

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.
Last edit: 11 months 3 weeks ago by DenisChenu.

Please Log in to join the conversation.

  • cheeseburger
  • cheeseburger's Avatar Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
11 months 3 weeks ago #243118 by cheeseburger
Hi. To help with your analysis: I just temp deactivated XSS and it did allow the greater than and less then symbols to display properly. However in our org we are required to keep it on.

Is it possible to update LS so it permits lone symbols such as greater than and less than when not in the context of an actual tag?

Also, early in this thread it was confirmed to be a bug. Do we still see it as a bug? If so, could someone continue to post that in the tracker? I know we were headed that direction but the conversation broke off into a secondary topic. 

I'm asking so we know how to communicate to our client. If it's not considered a bug, we will have to have them find an alternative method to present the question. We currently have them doing the same while awaiting the previous bug fix for array type F questions. We just need to know what status to communicate to them and to know if alternative solutions need to be found for the two outstanding challenges (possibly bugs). 

Thanks! 

Please Log in to join the conversation.

Lime-years ahead

Online-surveys for every purse and purpose