Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Goodbye Telerik !Goodbye Telerik !
Previous
 
Next
New Post
8/14/2014 12:12 PM
 
we've been moving away from their usage for a while (using SPA style applications with knockoutJS/service framework for a while), so theres not as much as you'd think e.g. we replaced various dropdowns for pages/modules etc., with new controls that dynamically load data via service framework requests. We'll continue this process, iteratively updating code over many versions (ideally implementing alternative code in the wrappers, but if not replacing the use of telerik wrapped controls), but the agreement with telerik gives us the ability to do this carefully in a planned fashion, rather than try to do everything in one big (likely to be buggy) release.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
10/9/2014 6:33 PM
 

Not sure if this impacts our Telerik versions.

"A tool that's popular with Microsoft's in-house developers, the RadEditor HTML editor, contains a dangerous cross-site scripting (XSS) vulnerability, researcher GS McNamara says."

http://www.theregister.co.uk/2014/10/01/researcher_details_nasty_xss_flaw_in_popular_web_editor/


Mutate and Survive
 
New Post
10/9/2014 6:41 PM
 

It's debateable how much of an issue it is as the syntax is limited to a small subset of very old browsers - the issue is minor as it only affects users of Internet Explorer 5.5-7 . Users of IE8 or above, or any other browser, cannot be affected. http://blogs.telerik.com/blogs/14-09-24/securing-radeditor-content-and-preventing-xss-attacks covers the details of why this is well.

Note: DNN users of DNN 6.0 and above can use the HTML Editor manager function to enable “RemoveScripts” to fix this issue. Alternatively DNN users can also opt to use an alternative HTML editor such as CkEditor http://www.dnnsoftware.com/wiki/page/html_editor_providers if they need to support IE 5.5, 6 or 7 clients.


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
10/10/2014 8:02 AM
 
Hi Cathal
I was pretty sure that you and DNN would have been aware of this and, if it was a problem, let us all know via an update.
I posted as it can sometimes be difficult to gauge severity from security postings (on other sites).

As an aside: I was recently at a very large bank in the City of London and saw a few systems that ran on a very early IE. It's still out there.

Thanks for all your work on DNN.

Ian 

Mutate and Survive
 
New Post
10/10/2014 9:29 AM
 
No problem Ian, we keep a careful watch on a number of security and vulnerability sites so are usually on top of things (my response is actually from an internal mail I sent 2 weeks ago - I must blog the details). As to the usage of early IE, not much we can do about that - however they are on OS versions that are no longer supported by Microsoft so a minor xss issue is the least of their worries :)

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Goodbye Telerik !Goodbye Telerik !


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out