We use the Cloudflare service for a site that uses RadEditor controls on several pages. When the Cloudflare web application firewall is turned on, a POST with HTML in a RadEditor control triggers several XSS and SQL Injection rules in the web application firewall. There were so many false positives that the web application firewall was immediately turned off.
Does anyone have experience resolving this issue by either changing the settings/configuration of the RadEditor controls, or by tweaking the Cloudflare Web Application Firewall rules?
Please note that I'm not suggesting that this is a flaw in the RadEditor control. The RadEditor provides an amazing amount of functionality.
Thanks