ANS-1659 · ROLES, PERMISSIONS & SECURITY
What Are the Security Implications of Enabling HTML in NetSuite Search Formulas?
Enabling HTML in NetSuite search formulas introduces specific security vulnerabilities that administrators should be aware of.
Short answer
Enabling HTML in NetSuite search formulas presents two primary security concerns: bypassing designed system security measures and the risk of malicious external links. Limitations in search results may exist for security reasons, and allowing HTML could circumvent these. Additionally, users with search building permissions might inadvertently or maliciously embed links to external threats, including redirected trusted domains.
Scenario
NetSuite administrators or users may consider enabling HTML within search formulas to achieve specific display or formatting requirements in search results. However, before doing so, it is crucial to understand the potential security implications this action could introduce to the NetSuite environment.
Solution
When HTML is enabled in NetSuite search formulas, two primary security concerns arise:
Bypassing Designed Security Measures
The system's search results often have inherent limitations, which may be intentionally implemented for security purposes. Introducing HTML into search formulas could potentially be exploited to bypass these designed security measures, leading to unintended data exposure or system manipulation.
Risk of External Threats via Links
There is no built-in mechanism to guarantee that users with permissions to create or modify searches will not embed HTML that links to external threats. This risk extends to scenarios where seemingly trusted external domains could be maliciously redirected by attackers, compromising user security upon clicking such links within NetSuite search results.
Expert NetSuite Support
Need help with this NetSuite issue?
Roles, Permissions & Security consulting and configuration support
