Description
Service parameter with allow-html="safe" does not check the OWASP sanitizer flag ie. enabled or not and perform sanitization which causing policy error while editing text data
getting following exception error:
"In field [textData] by our input policy, your input has not been accepted for security reason. Please check and modify accordingly, thanks."
Attachments
Attachments
Issue Links
- is blocked by
-
OFBIZ-11266 content/control/WebSiteCms?webSiteId=CmsSite fails
- Closed
- relates to
-
OFBIZ-10187 OWASP sanitizer breaks proper rendering of HTML code
- Closed