Details
-
Bug
-
Status: Closed
-
Resolution: Fixed
-
Master
-
- 7.4-known-issues
- 7.4.13-u41
- interns-BR
- liferay-ga22-ce-743-known-issues
- liferay-ga23-ce-743-known-issues
- liferay-ga24-ce-743-known-issues
- liferay-ga25-ce-743-known-issues
- liferay-ga26-ce-743-known-issues
- liferay-ga27-ce-743-known-issues
- liferay-ga28-ce-743-known-issues
- liferay-ga29-ce-743-known-issues
- liferay-ga30-ce-743-known-issues
- liferay-ga31-ce-743-known-issues
- liferay-ga32-ce-743-known-issues
- liferay-ga33-ce-743-known-issues
- liferay-ga34-ce-743-known-issues
- liferay-ga35-ce-743-known-issues
- liferay-ga36-ce-743-known-issues
- liferay-ga37-ce-743-known-issues
- liferay-ga38-ce-743-known-issues
- liferay-ga39-ce-743-known-issues
- liferay-ga40-ce-743-known-issues
- liferay-ga48-ce-743-known-issues
Description
Description:
Workflow Source is allowing user to turn code into characters
Steps to Reproduce:
- Go to Workflow > Process Builder
- Add a New Workflow and go to Source View
- Import the attached xml file and see the tag
<name>'"><script>alert(/def-name/)</script></name>
- Click on Diagram View button
- Click on Source view button
Expected Result:
The tag name should remain
<name>'"><script>alert(/def-name/)</script></name>
Actual Result:
The tag name has changed to
<name>'"><script>alert(/def-name/)</script></name
Verified on master : 3e03bc665911e43653095ffb59c1b94fe5a6d994