Our hosted account was breached via Word Press and the service provider implemented a "solution" from
SecureLive.
Part of that solution is to strip code entered from WYSIWYG editors out of POST commands to prevent XSS injections:
http://support.securelive.com/knowledgebase.php?article=15http://support.securelive.com/knowledgebase.php?article=12I'm hoping that our short-term solution will be to enter all resource URL's into the SP database and then into Pluslets from there, and not enter URLs via the editor.
However, wouldn't this kind of security "fix" render all SP instances broken? (and why isn't it a problem in this WYSSIWG app?)
Thoughts and comments addressing this matter would be most appreciated.
Thank you,
Peter