Details
-
Improvement
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
5.1 EE SP2 (5.1.5), 5.2 EE (5.2.4)
-
All
Description
HTML strings need to be escaped differently depending on how it's used. This improvement updates JSP files to follow the recommendations outline in http://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet
Attachments
Issue Links
- is related to
-
LPS-3633 Correctly escape HTML strings
-
- Reviewed
-