zackster
07/18/2023, 4:52 PMJordan Clark
07/19/2023, 3:28 PMapplication action="update" secure: false makes the entire application vulnerable with the hope that bad requests to other parts of the app don't happen at the same moment, but if your application was doing this often it would be left wide open.
It would be better if the whitelist was scoped to the current request or file only, like a cfprocessingdirective or better yet block scope:
cfprocessingdirective xmlSecure=false {
xml = xmlParse( trustedXml );
};zackster
07/19/2023, 3:46 PMgetApplicationSettings().xmlfeatures
while that's looping and dumping out the settings,
then call the unsafe.cfm which changes the xmlfeatures to be unsafe
nothing changes in the normal requestJordan Clark
07/19/2023, 5:11 PM