Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-18937

Remove HTML in "Text Editor" OpenSocial Gadget

    XMLWordPrintable

    Details

      Description

      The "Text Editor" OpenSocial Gadget is a vector of XSS attacks, and displaying arbitrary HTML must be removed.

      This does not apply to 7.10 or later due to removal of OpenSocial in NXP-16928.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                fguillaume Florent Guillaume
                Reporter:
                fguillaume Florent Guillaume
                Participants:
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: