Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
1.4.19, 1.5.3
-
None
Description
Markup escaping of the title and summary label in org.apache.wicket.extensions.wizard.WizardStep are disabled by default. This fact is not documented, an therefore there could be some security risk, when their Models are generated from user input.
An improvement would be to enable markup escaping and let the user disable this on demand.