Updated a SP2013 customer system to the December 2017 CU. The customer is running with a custom materpage which includes the allow framing option.
In the December 2017 CU the Allow framing option was included so when you apply the patch top a system that already has the allow framing options you will get an error when using the new form / edit form when creating / editing a list for example.
MS decided to again remove the allow framing option in the January 2018 CU.
Hope you will add this as a comment to the December 2017 / January 2018 CU update.
From the MS case I opened :
- AllowFraming was specifically added to ListFormWebpart class in the update Description of the security update for SharePoint Server 2016: November 14, 2017
- It was added for the below functionality
• You can now edit the SharePoint properties of a document directly in the Microsoft Word client through the SharePoint Properties panel. This experience requires a version of Microsoft Word that supports this functionality, such as the version that is included in Microsoft Office 365.
- However, the KB for SharePoint 2013 does not mention it but the same functionality was also ported to SharePoint 2013 through the update December 12, 2017, cumulative update for SharePoint Server 2013 (KB4011593)
- The fix for it was included in the update January 9, 2018, cumulative update for SharePoint Enterprise Server 2013 (KB4011652)
- The KB for 2013 Foundation talks about it Description of the security update for SharePoint Foundation 2013: January 9, 2018
You cannot load EditForm.aspx pages if you use a custom master page that contains allow framing web parts. You also receive the following error message:
Sorry, something went wrong
An unexpected error has occurred.
- Even though it is mentioned EditForm.aspx is affected but all forms that use ListFormWebpart are affected including NewForm.
- You have two options to fix this issue
1. Apply January 9, 2018, cumulative update for SharePoint Enterprise Server 2013 (KB4011652)
2. Remove the AllowFraming Server Tag from your custom master page.