Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
App CMS 1.1.0
-
None
Description
when we use sling-cms demo ,we find it that input in [+taxonomy item] may cause the XSS vulnerability。
some one like eg.
//代码占位符 "><svg onload=alert('xss')></svg>