-
Type:
Bug
-
Status: Closed
-
Resolution: Fixed
-
Affects Version/s: Master
-
Fix Version/s: 7.2.10 DXP FP2, 7.2.10.1 DXP SP1
-
Component/s: Fragment Administration
-
Fix Priority:4
-
Git Pull Request:
Steps to Reproduce:
- Enable Fragment Configurations
- Add a Page Fragment Section with a configuration of type text
- Create a new content page and add fragment
- Change the configuration text to be "<script>alert('test')</script>"
- Publish and view page
Expected Result:
Javascript is not executed
Actual Result:
Javascript is executed
Reproduced on:
Tomcat 9.0.17 + MySQL 5.7.
Portal Master GIT Commit: 5768543decf42efba87f23f0bc6a08f4152cd1a7