Anonymous Monk has asked for the wisdom of the Perl Monks concerning the following question:
I was reading http://hackerific.net/2015/01/16/avoid-xss-in-template-toolkit/ Avoid XSS in Template Toolkit
and then it occured to me! Should you escape every place a template variable is used? I mean I have a site where you make a choice using a Jquery slider which is send to the server through AJAX POST, and then Template::Toolkit displays the value entered.
In essence there is no form POST where the user can enter data freely.But,can the user still manipulate the posted data and should I use escaping for the posted slider data? Shoudl I escape ALL data passed to Template toolkit or in certain cases ?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Template toolkit XSS
by SimonPratt (Friar) on Aug 05, 2015 at 11:33 UTC | |
|
Re: Template toolkit XSS
by 1nickt (Canon) on Aug 05, 2015 at 00:38 UTC | |
by Anonymous Monk on Aug 05, 2015 at 01:57 UTC | |
|
Re: Template toolkit XSS
by Anonymous Monk on Aug 04, 2015 at 21:50 UTC | |
|
Re: Template toolkit XSS
by anonymized user 468275 (Curate) on Aug 05, 2015 at 08:55 UTC | |
by Anonymous Monk on Aug 05, 2015 at 09:07 UTC | |
by anonymized user 468275 (Curate) on Aug 05, 2015 at 10:57 UTC | |
by Anonymous Monk on Aug 05, 2015 at 11:12 UTC | |
by anonymized user 468275 (Curate) on Aug 05, 2015 at 14:26 UTC | |
| |
|
Re: Template toolkit XSS
by Anonymous Monk on Aug 05, 2015 at 01:34 UTC |