Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-9019

The XSSFilter will mark URLs containing both escaped characters and HTML entities as invalid

    XMLWordPrintableJSON

Details

    Description

      A URL similar to http://localhost/?q=a+b&r=1 will be marked as invalid by the XSSFilterImpl implementation. However, the URL provided is valid and should not be filtered.

      Attachments

        Activity

          People

            radu Radu Cotescu
            radu Radu Cotescu
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: