Details
-
Bug
-
Status: Closed
-
Resolution: Fixed
-
Master
-
7.3.x, 7.2.x, 7.1.x, 7.0.x
-
Committed
-
3
Description
Description: You are allowed to inject scripts in web content title.
Steps:
- Navigate to Product Menu > Content & Data > Web Content
- Add a Basic Web Content with title '<script>alert(123);</script>' and a content
- Publish it
- Edit the Web content
Expect result: No Alert.
Actual result: Alert 123 displayed.
Attachments
Issue Links
- is caused by
-
LPS-133314 Accessibility errors on search page portlet using OAW tool
- Closed