kjac / FormEditor

A form builder editor for Umbraco 7 - let your editors build forms easily with this free package.
MIT License
99 stars 42 forks source link

Security Issue? #207

Closed bobi33 closed 5 years ago

bobi33 commented 5 years ago

Hi there,

I have received 3 contact form requests through this form from what appears to be a spam bot indicating some type of ransomwear:

"Hey. Soon your hosting account and your domain [website] will be blocked forever, and you will receive tens of thousands of negative feedback from angry people.

Here is a list of what you get if you don’t follow my requirements:

Is there any security concern regarding the contact form?

kjac commented 5 years ago

Hi there. Well, reCAPTCHA is supported out of the box. It's really good for spam protection on your forms.

Read more about it in the docs.

bobi33 commented 5 years ago

Hi, it looks like it got through reCAPTCHA. I am just trying to assess the potential security risk if they inject some type of code into the form to spam the website. I found a few examples of this on the internet.