| Some features of the MODx CMS (Content Management System) such as "Chunks" in MODx Revolution may trigger mod_security rules on the server. Since post data is not encapsulated, if you send any type of HTML, PHP or Javascript tags through this method it is flagged as an attempted cross-site scripting hack or similar dangerous behaviour. MODx has known about these issues since 2008 according to complaints on their support forums, but has yet to take the issue seriously - instead, they suggest disabling mod_security for the account or the entire server - severely compromising the security of the server and all it's users.
If you are a shared hosting customer, we can individually "whitelist" certain rules on your account that MODx triggers as we discover them but we will not disable mod_sec altogether. If you are experiencing random issues or even "404" errors when saving data, especially if it contains special characters or HTML tags please notify us and provide steps to reproduce the situation so we can determine if it is caused by mod_security. If so, we will do what we can to make it work with your account. |