kentico_jurajo
-
12/14/2009 2:40:01 AM
RE:Potential cross-site request forgery with BizForms
Hi,
In general you are right, but we cannot do this in general since some users may require this current behavior. It also depends on the field type.
In this case, you can create your custom form control for this, e.g. a textbox and you will encode its value by default, so the cross site attack won't be possible.
Best Regards, Juraj Ondrus
|