Results 1 to 6 of 6

Hybrid View

  1. #1
    Join Date
    Apr 2009
    Posts
    85
    Plugin Contributions
    0

    Default Sanitize contact form user input

    I am using version 1.3.8a, and our site just failed the PCI compliance test that happens every 3 months.

    They say the issue is "It appears that the cross-site scripting is flagging because the email section of the contact form is not sanitizing user input. Our code is being returned in full from that field. Please request your web developer to properly sanitize user input for this field."

    Anyone know the easiest way to sanitize user input on the contact form?

    Thanks much!

  2. #2
    Join Date
    Jun 2003
    Posts
    33,720
    Plugin Contributions
    0

    Default Re: Sanitize contact form user input

    You need to upgrade ASAP. That version has known vulnerabilities
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  3. #3
    Join Date
    Apr 2009
    Posts
    85
    Plugin Contributions
    0

    Default Re: Sanitize contact form user input

    Is the upgrade easy to do myself?

  4. #4
    Join Date
    May 2010
    Location
    WA State
    Posts
    1,678
    Plugin Contributions
    3

    Default Re: Sanitize contact form user input


  5. #5
    Join Date
    Apr 2009
    Posts
    85
    Plugin Contributions
    0

    Default Re: Sanitize contact form user input

    This looks quite complex. Is it something you think I should be able to do on my own? I'm somewhat web savvy but I did not do the original install of zencart.

  6. #6
    Join Date
    Jul 2005
    Location
    Upstate NY
    Posts
    22,010
    Plugin Contributions
    25

    Default Re: Sanitize contact form user input

    That depends largely on how much customization your site has, and whether it was done properly using the template/override system. You do need to be able to follow instructions correctly.

 

 

Similar Threads

  1. User Input Pricing?
    By cPappas91 in forum General Questions
    Replies: 5
    Last Post: 16 Nov 2010, 06:19 PM
  2. Custom Contact Form - New Input Fields
    By Nima in forum Templates, Stylesheets, Page Layout
    Replies: 5
    Last Post: 3 Jun 2010, 11:45 PM
  3. Contact US page + One more Contact FORM :blink:
    By Orange Wacko in forum Managing Customers and Orders
    Replies: 0
    Last Post: 21 Jul 2009, 10:29 PM
  4. SPAM from ‘Contact Us’ form, even though form is removed
    By Beer_man in forum General Questions
    Replies: 5
    Last Post: 3 Dec 2008, 02:40 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg