A customer running an intranet on a version 9.5.1 installation of DynamicWeb have their IP's banned on a regular basis for no apparent reason. Last time it happened to them was because one of them attempted to create a post through a regular frontend form. He got the following message in the log:
2018-10-05T14:34:08;Injection ban: Match on Besked_IT (((\%3C)|<|\[)((\%2F)|\/)*(?:script|url|a\W|img|svg|iframe)+.*?((\%3E)|>|\]))
What might be causing this, and how can it be solved? Preferably without allowing SQL injections.
/ Roald