Project

General

Profile

Actions

BUG #4229

open

BUG #4247: [SQA][MODULE] Agency Profile Setup

BUG #4249: [SQA]: Functional >> Agency Profile Setup

[SQA] Agency Profile: Add Project fields allow unsafe HTML/JavaScript input

Added by Aman Bhuiyan 2 months ago. Updated 29 days ago.

Status:
Complete
Priority:
High
Assignee:
Target version:
Start date:
02/03/2026
Due date:
% Done:

100%

Estimated time:
Spent time:

Description

Description

Module/Section: Agency Profile → Project
Profile: Agency
Issue Category: Functional

The Add Project input fields (Project Title, Project Overview, Category) on the Agency Profile page do not sanitize user input, allowing HTML and JavaScript tags.
This creates a potential security risk and may affect data integrity.

Steps to Reproduce

  1. Navigate to the Agency Profile page.
  2. Open Projects → Add Project.
  3. Enter HTML/JS tags (e.g., <b>test</b> or <script>alert(1)</script>) in Project Title, Project Overview, or Category.
  4. Save the project.

Expected Result

The Project input fields should sanitize or reject HTML/JavaScript tags and accept only safe text input.

Actual Result

The fields accept HTML/JavaScript tags without validation, creating a security vulnerability.

Attachments


Impact Area:

Root Cause:


Additional Info

  • Tested By: Aman
Actions #1

Updated by Ayat Rahman 2 months ago

  • Parent task set to #4249
Actions #2

Updated by Ayat Rahman about 2 months ago

  • Assignee changed from Ayat Rahman to Aman Bhuiyan
  • % Done changed from 0 to 100
Actions #3

Updated by Aman Bhuiyan 29 days ago

  • Status changed from Pending to Complete
Actions

Also available in: Atom PDF