6.0.0-alpha12
6/8/25

[#3900] Reply To is not escaped properly
Summary Reply To is not escaped properly
Queue IMP
Queue Version 4.1.1
Type Bug
State Resolved
Priority 3. High
Owners Horde Developers (at)
Requester phyre (at) rogers (dot) com
Created 05/08/2006 (6971 days ago)
Due
Updated 05/10/2006 (6969 days ago)
Assigned 05/09/2006 (6970 days ago)
Resolved 05/10/2006 (6969 days ago)
Github Issue Link
Github Pull Request
Milestone
Patch No

History
05/10/2006 05:47:19 AM Michael Slusarz Comment #5
State ⇒ Resolved
Reply to this comment
This was nothing more than a typo and has been fixed in IMP 4.1.2.
05/10/2006 05:43:05 AM Michael Slusarz Comment #4 Reply to this comment
I can reproduce also, but only w/FW_3 (works fine in HEAD).
05/09/2006 10:25:38 PM Jan Schneider Comment #3 Reply to this comment
Yes.
05/09/2006 10:17:57 PM Chuck Hagenbuch Comment #2
State ⇒ Feedback
Reply to this comment
I can't reproduce this - Jan, can you?
05/09/2006 10:57:40 AM Jan Schneider Priority ⇒ 3. High
 
05/09/2006 10:55:09 AM Jan Schneider Assigned to Horde DevelopersHorde Developers
State ⇒ Assigned
 
05/08/2006 05:51:02 PM phyre (at) rogers (dot) com Comment #1
Priority ⇒ 1. Low
Type ⇒ Bug
Summary ⇒ Reply To is not escaped properly
Queue ⇒ IMP
State ⇒ Unconfirmed
Reply to this comment
An e-mail containing:

   Reply-To: <user@domain.com>

Appears in the message view with the 'Reply-To:' column visible [as it 
should] however does not parse/escape this field.



The result is a <user@domain.com> being embedded in the html of the 
message.  In theory, one could probably find a way to put html into 
the reply-to address and mess with display or even add a security issue.



Ideally, the reply-to field should be shown as an e-mail link in the 
same way that the from address should, and should not simply be copied 
into the html of the page.



[note- this issue may affect other fields as well?  Haven't looked 
into it just yet, but <> in headers should always be changed to 
&lt;&gt;.

In this case, it'd be best to interpret it as an e-mail address however.

Saved Queries