Details
-
Bug
-
Status: Closed
-
Resolution: Fixed
-
Master
Description
Steps to Reproduce:
- Enable Fragment Configurations
- Add a Page Fragment Section with a configuration of type text
- Create a new content page and add fragment
- Change the configuration text to be "<script>alert('test')</script>"
- Publish and view page
Expected Result:
Javascript is not executed
Actual Result:
Javascript is executed
Reproduced on:
Tomcat 9.0.17 + MySQL 5.7.
Portal Master GIT Commit: 5768543decf42efba87f23f0bc6a08f4152cd1a7