Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-99785

Javascript executes in fragment configuration type text

Details

    Description

      Steps to Reproduce:

      1. Enable Fragment Configurations
      2. Add a Page Fragment Section with a configuration of type text
      3. Create a new content page and add fragment
      4. Change the configuration text to be "<script>alert('test')</script>"
      5. Publish and view page

      Expected Result:

      Javascript is not executed

      Actual Result:

      Javascript is executed

       

      Reproduced on:

      Tomcat 9.0.17 + MySQL 5.7.
      Portal Master GIT Commit: 5768543decf42efba87f23f0bc6a08f4152cd1a7

      Attachments

        Issue Links

          Activity

            People

              brooke.dalton Brooke Dalton
              brooke.dalton Brooke Dalton
              Kiyoshi Lee Kiyoshi Lee
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:
                3 years, 26 weeks, 5 days ago

                Packages

                  Version Package
                  7.2.10 DXP FP2
                  7.2.10.1 DXP SP1