# Mod Security

**URL:** <https://forum.mautic.org/t/mod-security/12413>\
**Category:** Product Support\
**Created:** [January 23, 2020, 6:07pm UTC](https://forum.mautic.org/t/mod-security/12413 "2020-01-23T18:07:54Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![yorkshirecl](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/yorkshirecl/32/1512_2.png) [@yorkshirecl](https://forum.mautic.org/u/yorkshirecl)\
**Post date:** [January 23, 2020, 6:07pm UTC](https://forum.mautic.org/t/mod-security/12413/1 "2020-01-23T18:07:55Z")

</div>

**Your software**  
My Mautic version is: 2.15.2  
My PHP version is: 7.2

**Your problem**  
My problem is: I’m experiencing trouble saving using my self hosted version Mautic. Currently I’ve come across this issue when I try to save email templates or create landing pages. My host has resolved these two issues but I still have trouble using code mode.

These errors are showing in the log (from host):

> 2020-01-21 07:33:06.773058 [NOTICE] [24806] [85.92.65.92:52431:HTTP2-131] mod\_security rule [Id ‘212970’] at [/etc/apache2/conf.d/modsec\_vendor\_configs/comodo\_litespeed/07\_XSS\_XSS.conf:135] triggered!  
> [modsecurity] [Tue Jan 21 07:33:06 2020] [error] [client 85.92.65.92] ModSecurity: Access denied with code 403, [Rule: ‘REQUEST\_URI|ARGS\_POST|ARGS\_NAMES|REQUEST\_COOKIES|REQUEST\_COOKIES\_NAMES|XML:/\*|!ARGS:/body/|!ARGS:/content/|!ARGS:/description/|!ARGS:emailglobalheader|!ARGS:Post|!ARGS:desc|!ARGS:html\_message|!ARGS:text|!REQUEST\_COOKIES:/\_\_utm/|!REQUEST\_COOKIES:/\_pk\_ref/’ ‘@rx \<meta.{0,}?charset/{0,}=’] [id “212970”] [rev “5”] [msg “COMODO WAF: IE XSS Filters - Attack Detected.”] [logdata "Matched Data: \<metahttp-equiv=“content-type"content=“text/html;charset= found within \<!doctypehtmlpublic”-//w3c//dtdxhtml1.0transitional//en”"[http://www.w3.org/tr/xhtml1/dtd/xhtml1-transitional.dtd"\>\<htmlxmlns=“http://www.w3.org/1999/xhtml”\>\<head\>\<metahttp-equiv="content-type"content=“text/html;charset=utf-8”/\>\<metaname=“viewport"content=“width=device-width,initial-scale=1.0”\>\<title\>{subject}\</title\>\<styletype=“text/css”\>@importurl(https://fonts.googleapis.com/css?family=lato:400);img{max-width:600px;outlin...”](http://www.w3.org/tr/xhtml1/dtd/xhtml1-transitional.dtd%22%3E%3Chtmlxmlns=%22http://www.w3.org/1999/xhtml%22%3E%3Chead%3E%3Cmetahttp-equiv=%22content-type%22content=%22text/html;charset=utf-8%22/%3E%3Cmetaname=%22viewport%22content=%22width=device-width,initial-scale=1.0%22%3E%3Ctitle%3E%7Bsubject%7D%3C/title%3E%3Cstyletype=%22text/css%22%3E@importurl(https://fonts.googleapis.com/css?family=lato:400);img%7Bmax-width:600px;outlin...%22)] [severity “CRITICAL”] [tag “CWAF”] [tag “XSS”]

Steps I have tried to fix the problem:

I have contracted my host and they have applied various rules to allow the software to run but this weakens the overall security of my site. Are you able to provide a fix in the software so these rules are not triggered?

I’m not very familiar with XSS and mod security but your software is fantastic and I’d like to start using it.
