-
Type:
Bug
-
Resolution: Fixed
-
Affects Version/s: None
-
Component/s: TermPortal
-
High
-
None
-
-
None
-
Emptyshow more show less
Problem
Certain XSS scenarios are currently possible with user-input data - in Translate5 editor's right-side TermPortlet, and across many places in TermPortal (search results, query autocomplete, filter window, active filters, etc)
Solution
All html entities within user-input data should be escaped prior using in UI - both in TermPortlet and TermPortal